Network Management

Applying Microsoft ASP.NET Core and .NET Desktop Runtime Security Patches on the Windows Servers running SolarWinds Platform

This article provides information about best practices for applying ASP.NET Core and .NET Desktop Runtime security patches to mitigate security vulnerabilities in environments running SolarWinds Platform.

First published date

10/2/2025 5:00 PM

Last published date

6/8/2026 3:25 PM

Overview

The SolarWinds Platform relies on Microsoft ASP.NET Core and .NET Desktop Runtime. Microsoft regularly releases security patches to address vulnerabilities in Microsoft ASP.NET Core and .NET Desktop Runtime. These updates are considered third-party maintenance and are not supported directly by SolarWinds. However, SolarWinds recommends updating to the latest version of Microsoft ASP.NET Core and .NET Desktop Runtime to maintain a secure and stable environment. 

This article provides guidance on: 

  • Verifying the current Microsoft ASP.NET Core and .NET Desktop Runtime
  • Registry setting for .NET Automatic Updates on the Server Operating Systems
  • Locating and downloading the latest patch from Microsoft per CVE
  • Safely applying updates with minimal impact to SolarWinds operations 

While no specific error messages are tied to unpatched Microsoft ASP.NET Core and .NET Desktop Runtime, failure to apply updates may expose your environment to known risks as outlined in Microsoft Security Bulletins.

Product section

Orion Platform

Cause

Vulnerabilities in Microsoft ASP.NET Core and .NET Desktop Runtime that require patching, as identified and remediated by Microsoft security updates. These are not caused by SolarWinds software but by external factors in the Microsoft ASP.NET Core and .NET Desktop Runtime ecosystem. 

Resolution

Important! When patching ASP.NET Core or .NET Desktop Runtime, SolarWinds recommends upgrading both components, even if the vulnerability appears to affect only one. Running different versions of ASP.NET Core and .NET Desktop Runtime on the same server can cause SolarWinds Platform services to fail.

 

To apply Microsoft ASP.NET Core and .NET Desktop Runtime updates: 

  1. Verify the current Microsoft ASP.NET Core and .NET Desktop Runtime version: 

  1. Opting in for automatic updates: 

  1. Microsoft Security Update link: 

 

 

Before proceeding with the update, follow these best practices to ensure minimal downtime and data protection: 

 

Important Notice: 

 

Take a full backup of the database server(s), including the SolarWinds databases. 

Take a snapshot or backup of all SolarWinds server(s) for quick rollback if needed. 

 

  1. Stop all SolarWinds services on all SolarWinds servers. If High Availability (HA) is deployed, disable it temporarily to prevent failover issues.
  2. Install the Microsoft ASP.NET Core and .NET Desktop Runtime on the affected Windows server.
  3. If the update requires a reboot, perform it in the following sequence:
  4. Reboot the database server first.
  5. Reboot SolarWinds servers as needed.
  6. Restart SolarWinds services and re-enable HA if applicable.
  7. Verify SolarWinds functionality post-update, such as checking database connectivity and monitoring dashboards.