Description of the security update for the remote code execution vulnerability in Microsoft Visual Studio 2013 Update 5: June 13, 2023 (KB5026610)

Applies To
Visual Studio 2013 Update 5

Note

Applies to: All Visual Studio 2013 Update 5 editions except Integrated Shells, Build Tools, and Remote Tools.

Summary

A remote code execution vulnerability exists in Microsoft Visual Studio 2013 when it incorrectly handles debug information.

To learn more about the vulnerability, see CVE-2023-21808, CVE-2023-23381, CVE-2023-24897, and CVE-2023-21815.

How to obtain and install the update

Method 1: Microsoft Download

The following file is available for download:

78af609e-f711-2638-de00-ccbc586124ad  Download the hotfix package now.

Method 2: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog website.

More information

Prerequisites

To apply this security update, you must have Visual Studio 2013 Update 5 installed.

Restart requirement

We recommend that you close Visual Studio 2013 before you install this security update. Otherwise, you may have to restart the computer after you apply this security update if a file that is being updated is open or in use by Visual Studio.

Security update replacement information

This security update doesn't replace other security updates.

File hash information

File name SHA256 hash
vs12-kb5026610.exe EC35DB29AA40EA7F23A58C559A1B9B3A82E7DCCC2D03B92134D510AB100A58D2

File information

File name File version File size Date Time
vs12-kb5026610.exe 12.0.40700.0 32,608,344 27-Mar-23 13:29

Installation verification

To verify that this security update is applied correctly, follow these steps:

  1. Open the Visual Studio 2013 program folder.
  2. Locate one or more of the following files.
    vc\bin\bscmake.exe
    vc\bin\amd64\bscmake.exe
    common7\ide\msdia120.dll
    common7\ide\remote debugger\x64\msdia120.dll
    common7\ide\remote debugger\x86\msdia120.dll
    common7\packages\debugger\msdia120.dll
    dia sdk\bin\msdia120.dll
    dia sdk\bin\amd64\msdia120.dll
    dia sdk\bin\arm\msdia120.dll
    team tools\dynamic code coverage tools\msdia120.dll
    team tools\performance tools\x64\msdia120.dll
    common7\ide\msobj120.dll
    team tools\performance tools\x64\msobj120.dll
    vc\bin\msobj120.dll
    vc\bin\amd64\msobj120.dll
    common7\ide\mspdbst.dll
    team tools\performance tools\mspdbcore.dll
    team tools\performance tools\mspdbst.dll
    team tools\performance tools\x64\mspdbcore.dll
    team tools\performance tools\x64\mspdbst.dll
    vc\bin\mspdb120.dll
    vc\bin\ mspdbcore.dll
    vc\bin\amd64\mspdb120.dll
    vc\bin\amd64\mspdbcore.dll
    vc\bin\amd64\mspdbst.dll
    team tools\performance tools\mspdbsrv.exe
    team tools\performance tools\x64\mspdbsrv.exe
    vc\bin\mspdbsrv.exe
    vc\bin\amd64\mspdbsrv.exe
  3. Verify that the file version is equal to or greater than 12.0.40700.0.

Information about protection and security

Protect yourself online: Windows Security support

Learn how we guard against cyber threats: Microsoft Security