Applies to: All Visual Studio 2015 Update 3 editions except Build Tools
Notice
In November 2020, the content of this article was updated to clarify the affected products, prerequisites, and restart requirements. Additionally, the update metadata in WSUS was revised to fix a Microsoft System Center Configuration Manager reporting bug.
Summary
An elevation of privilege vulnerability exists if the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector does not correctly handle objects in memory, or if the Diagnostics Hub Standard Collector Service incorrectly handles file operations.
To learn more about the vulnerability, go to CVE-2020-1257, CVE-2020-1293, CVE-2020-1278, CVE-2020-1203, and CVE-2020-1202.
How to obtain and install the update
Visual Studio 2015 Update 3
Method 1: Microsoft Download
The following file is available for download:
Method 2: Microsoft Update Catalog
To get the standalone package for this update, go to the Microsoft Update Catalog website.
Remote Tools for Visual Studio 2015 Update 3
To download the updated Remote Tools for Visual Studio 2015 Update 3, go to the following Microsoft webpage:
More information
Prerequisites
To apply this security update, you must have both Visual Studio 2015 Update 3 and the subsequent Cumulative Servicing Release KB 3165756 installed. Typically, KB 3165756 is installed automatically when you install Visual Studio 2015 Update 3. However, in some cases, you have to install the two packages separately.
Restart requirement
We recommend that you close Visual Studio 2015 before you install this security update. Otherwise, you may have to restart the computer after you apply this security update if a file that is being updated is open or in use by Visual Studio.
Security update replacement information
This security update supersedes KB4538032.
File hash information
File name |
SHA1 hash |
SHA256 hash |
---|---|---|
vs14-kb4562053.exe |
DEFC88E3181AB2322382B978BA2F29B08EC586D2 |
60372C699D24B093FB3AA047C2141F0667F331B85931BEE8FC922C51CEEB165D |
Installation verification
To verify that this security update is applied correctly, follow these steps:
-
Open the Visual Studio 2015 folder.
-
Locate the DiagnosticHub.StandardCollector.Runtime.dll file.
-
Verify that the file version is equal to or greater than 14.0.27541.0.
Information about protection, security, and support
-
Protect yourself online: Windows Security support
-
Learn how we guard against cyber threats: Microsoft Security
-
Obtain localized support per your country: International Support
-
Get more information about the Visual Studio support policy: Visual Studio Product Lifecycle and Servicing.