Applies to: All Visual Studio 2015 Update 3 editions except Build Tools
Notice
-
In November 2020, the content of this article was updated to clarify the affected products, prerequisites, and restart requirements.
-
This security update has been replaced by a newer update. For more information, see Description of the security update for the elevation of privilege vulnerability in Visual Studio 2015 Update 3 (4463110).
Summary
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations. CVE-2018-0952.
To learn more about the vulnerability, go toMore information
Prerequisites
Toapply this security update, you must have both Visual Studio 2015 Update 3 and the subsequent Cumulative Servicing Release KB 3165756 installed. Typically, KB 3165756 is installed automatically when you install Visual Studio 2015 Update 3. However, in some cases, you have to install the two packages separately.
Restart requirement
We recommend that you close Visual Studio 2015 before you install this security update. Otherwise, you may have to restart the computer after you apply this security update if a file that is being updated is open or in use by Visual Studio.
File hash information
File name |
SHA1 hash |
SHA256 hash |
---|---|---|
vs14-kb4456688.exe |
DE8F98515B7DBAB04B9B8468C2E4C33E2021CE34 |
4DF8D3BDC5CA501C391539BE790CE5B82CE185F63D3CB1BE095302A7C8C994A7 |
Information about protection, security, and support
-
Protect yourself online: Windows Security support
-
Learn how we guard against cyber threats: Microsoft Security
-
Obtain localized support per your country: International Support
-
Get more information about the Visual Studio support policy: Visual Studio Product Lifecycle and Servicing.