| Vuln ID | Severity | Asset | STIG | Title | Status | Doc Status | Assigned To | Actions |
|---|---|---|---|---|---|---|---|---|
| V-225229 | CAT II | SCHR-P3-DP-001 | Microsoft DotNet Framework 4.0 Security ... | .Net Framework versions installed on the system mu... | - | |||
Check TextDetermine which versions of the .NET Framework are installed by opening the directory %systemroot%\Microsoft.NET. The folder named "%systemroot%\Microsoft.NET\Framework" contains .NET files for 32 bit systems. The folder named "%systemroot%\Microsoft.NET\Framework64" contains .NET files for 64 bit systems. 64 bit systems will have both the 32 bit and the 64 bit folders. 32 bit systems do not have a Framework64 folder. Within each of the folders are the individual folder names that contain the corresponding versions of the .NET Framework: v4.0.30319 v3.5 v3.0 v2.0.50727 v1.1.4322 v1.0.3705 Search for all the Mscorlib.dll files in the %systemroot%\Microsoft.NET\Framework folder and the %systemroot%\Microsoft.NET\Framework64 folder if the folder exists. Click on each of the files, view properties, and click the version tab to determine the version installed. If there is no Mscorlib.dll, there is no installed version of .Net Framework in that directory. More specific information on determining versions of .Net Framework installed can be found at the following link. http://support.microsoft.com/kb/318785 Verify extended support is available for the installed versions of .Net Framework. Verify the .Net Framework support dates with Microsoft Product Lifecycle Search link. http://support.microsoft.com/lifecycle/search/?sort=PN&alpha=.NET+Framework Beginning with .NET 3.5 SP1, the .NET Framework is considered a Component of the Windows OS. Components follow the Support Lifecycle policy of their parent product or platform. .NET Framework 3.5 cannot function without the .NET Framework 2.0 and the .NET Framework 3.0, because there is no common language runtime (CLR) in the .NET Framework 3.5 layer. Therefore, when the .NET Framework 3.5 product is installed, the .NET Framework 2.0 and the .NET Framework 3.0 SP products are also installed. Installation of .NET 2.0 and 3.0 SP products as part of .NET Framework 3.5 is Not a Finding. (https://support.microsoft.com/en-us/topic/clarification-on-the-support-life-cycle-for-the-net-framework-3-5-the-net-framework-3-0-and-the-net-framework-2-0-28621c7b-226c-7682-27f5-2e2a42db39c3) If any versions of the .Net Framework are installed and support is no longer available, this is a finding. Fix TextRemove unsupported versions of the .NET Framework and upgrade legacy applications that utilize unsupported versions of the .NET framework. Finding DetailsEvaluate-STIG 1.2601.0 (Scan-NETFramework4_Checks) found this to be NOT A FINDING on 03/05/2026 ResultHash: 69B5FA47DB52CEE6EE623CD1C66B970ACFE69DFB ~~~~~ Operating system: --------------------------------- Name: Microsoft Windows Server 2022 Standard [21H2] Version: 10.0.20348 Enabled .NET Windows features: --------------------------------- NET-Framework-45-Core Library files: --------------------------------- File Path: C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll Version: 4.8.4795.0 File Path: C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorlib.dll Version: 4.8.4795.0 Ref - https://learn.microsoft.com/en-us/lifecycle/products/microsoft-net-framework Ref - https://support.microsoft.com/en-us/topic/clarification-on-the-support-life-cycle-for-the-net-framework-3-5-the-net-framework-3-0-and-the-net-framework-2-0-28621c7b-226c-7682-27f5-2e2a42db39c3
Source: SCHR-P3-DP-001_DotNET4_V2R7_20260305-132722.cklb
Scan Date: 2026-03-12T15:38:14.388995
Technology Area: Windows Operating System
|
||||||||