Description of the security update for the Diagnostics Hub Standard Collector elevation of privilege vulnerability in Visual Studio 2015 Update 3: December 11, 2018

S'aplica a: Visual Studio 2015 Update 3

Applies to: Visual Studio 2015 Update 3 Community, Professional, Enterprise, and Remote Tools. 

Does not apply to: Build Tools, Visual Studio 2015 Isolated and Integrated Shells.

Note: On October 8, 2019, we released improvements to our offering method for this update on Microsoft Update that ensure this update is offered to all appropriate configurations.

Summary


An elevation of privilege vulnerability exists if the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.

To learn more about the vulnerability, go to CVE-2018-8599.

More information


Prerequisites

To apply this security update, you must have Visual Studio 2015 Update 3 installed.

Replacement information

This update replaces security update 4463110.

How to obtain and install the update


Visual Studio 2015 Update 3

Method 1: Microsoft Download

The following file is available for download:

Download Download the hotfix package now.

Note You must restart your computer before you install this update. 

Method 2: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog website.

Visual Studio 2015 Remote Tools

To download the updated remote tools for Visual Studio 2015 Update 3, go to the following Microsoft webpage:

Download Visual Studio 2015 Update: Remote Tools

File information


File information
the English (United States) version of this software update installs files that have the attributes that are listed in the following tables. the dates and the times for these files are listed in Coordinated Universal Time (UTC). the dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

Installation verification


To check that this security update was applied correctly, follow these steps:

  1. Open the Visual Studio 2015 folder.
  2. Locate the DiagnosticHub.StandardCollector.Runtime.dll file.
  3. Verify that the file version is equal to or greater than 14.0.27529.