Network Management
Applying Microsoft ASP.NET Core and .NET Desktop Runtime Security Patches on the Windows Servers running SolarWinds Platform
This article provides information about best practices for applying ASP.NET Core and .NET Desktop Runtime security patches to mitigate security vulnerabilities in environments running SolarWinds Platform.
First published date
Last published date
Overview
The SolarWinds Platform relies on Microsoft ASP.NET Core and .NET Desktop Runtime. Microsoft regularly releases security patches to address vulnerabilities in Microsoft ASP.NET Core and .NET Desktop Runtime. These updates are considered third-party maintenance and are not supported directly by SolarWinds. However, SolarWinds recommends updating to the latest version of Microsoft ASP.NET Core and .NET Desktop Runtime to maintain a secure and stable environment.
This article provides guidance on:
- Verifying the current Microsoft ASP.NET Core and .NET Desktop Runtime
- Registry setting for .NET Automatic Updates on the Server Operating Systems
- Locating and downloading the latest patch from Microsoft per CVE
- Safely applying updates with minimal impact to SolarWinds operations
While no specific error messages are tied to unpatched Microsoft ASP.NET Core and .NET Desktop Runtime, failure to apply updates may expose your environment to known risks as outlined in Microsoft Security Bulletins.
Product section
Cause
Vulnerabilities in Microsoft ASP.NET Core and .NET Desktop Runtime that require patching, as identified and remediated by Microsoft security updates. These are not caused by SolarWinds software but by external factors in the Microsoft ASP.NET Core and .NET Desktop Runtime ecosystem.
Resolution
| Important! When patching ASP.NET Core or .NET Desktop Runtime, SolarWinds recommends upgrading both components, even if the vulnerability appears to affect only one. Running different versions of ASP.NET Core and .NET Desktop Runtime on the same server can cause SolarWinds Platform services to fail. |
To apply Microsoft ASP.NET Core and .NET Desktop Runtime updates:
-
Verify the current Microsoft ASP.NET Core and .NET Desktop Runtime version:
-
Follow the guidance at: Check installed .NET versions on Windows, Linux, and macOS - .NET | Microsoft Learn
-
Opting in for automatic updates:
-
Refer to the list at: .NET Automatic Updates for Server Operating Systems - .NET Blog
-
Microsoft Security Update link:
-
CVE-2025-30399 - CVE-2025-30399 - Security Update Guide - Microsoft - .NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-55315 - CVE-2025-55315 - Security Update Guide - Microsoft - ASP.NET Security Feature Bypass Vulnerability
- CVE-2025-55247 - CVE-2025-55247 - Security Update Guide - Microsoft - .NET Elevation of Privilege Vulnerability
- CVE-2025-55248 - CVE-2025-55248 - Security Update Guide - Microsoft - .NET, . NET Framework and Visual Studio Information Disclosure Vulnerabilities
- CVE-2026-21218 - CVE-2026-21218 - Security Update Guide - Microsoft - .NET Spoofing Vulnerability
- CVE-2026-35433 - CVE-2026-35433 - Security Update Guide - Microsoft - .NET Elevation of Privilege Vulnerability
- CVE-2026-42899 - CVE-2026-42899 - Security Update Guide - Microsoft - ASP.NET Core Denial of Service Vulnerability
- CVE-2026-32175 - CVE-2026-32175 - Security Update Guide - Microsoft - .NET Core Tampering Vulnerability
- CVE-2026-32177 - CVE-2026-32177 - Security Update Guide - Microsoft - .NET Elevation of Privilege Vulnerability
Before proceeding with the update, follow these best practices to ensure minimal downtime and data protection:
Important Notice:
|
Take a full backup of the database server(s), including the SolarWinds databases. Take a snapshot or backup of all SolarWinds server(s) for quick rollback if needed. |
- Stop all SolarWinds services on all SolarWinds servers. If High Availability (HA) is deployed, disable it temporarily to prevent failover issues.
- Install the Microsoft ASP.NET Core and .NET Desktop Runtime on the affected Windows server.
- If the update requires a reboot, perform it in the following sequence:
- Reboot the database server first.
- Reboot SolarWinds servers as needed.
- Restart SolarWinds services and re-enable HA if applicable.
- Verify SolarWinds functionality post-update, such as checking database connectivity and monitoring dashboards.