Description of the security update for Microsoft Visual Studio 2015 Update 3: July 14, 2020

Applies to: Visual Studio 2015 Update 3

Applies to: Visual Studio 2015 Update 3 Community, Professional, Enterprise, and Remote Tools

Does not apply to: Build Tools, Visual Studio 2015 Isolated and Integrated Shells

Summary


An elevation of privilege vulnerability exists if the Visual Studio Standard Collector Service does not correctly sanitize input. This condition causes an insecure library-loading behavior.

To learn more about the vulnerability, go to CVE-2020-1393.

How to obtain and install the update


Visual Studio 2015 Update 3

Method 1: Microsoft Download

The following file is available for download:

Download Download the hotfix package now.

Method 2: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog website. 

Visual Studio 2015 Remote Tools

To download the updated remote tools for Visual Studio 2015 Update 3, go to the following Microsoft webpage:

Download Visual Studio 2015 Update: Remote Tools

More information


Prerequisites

To apply this security update, you must have Visual Studio 2015 Update 3 installed.

Restart requirement

You may have to restart the computer after you apply this security update if an instance of Visual Studio is being used.

Security update replacement information

This security update doesn't replace other security updates.

Deployment information

For deployment details for this security update, see the following Knowledge Base article:

Security update deployment information: June 9, 2020

File hash information

File name SHA1 hash SHA256 hash
vs14-kb4567703.exe 0FEC68D3DC4482550D47A94E9E2D4FA4A82EC7AB 9FE64E91CC6507F0BDD5DD33F1284C904F5E39986F499C7296974CF4E7EDCE20


File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

To verify that this security update is applied correctly, follow these steps:

  1. Open the Visual Studio 2015 folder.
  2. Locate the DiagnosticHub.StandardCollector.Runtime.dll file.
  3. Verify that the file version is equal to or greater than 14.0.27542.0.

Information about protection and security


Protect yourself online: Windows Security support

Learn how we guard against cyber threats: Microsoft Security