Description of the security update for the elevation of privilege vulnerability in Visual Studio 2015 Update 3: September 11, 2018

Applies to: All Visual Studio 2015 Update 3 editions except Build Tools

Notice

In November 2020, the content of this article was updated to clarify the affected products, prerequisites, and restart requirements. Additionally, the update metadata in WSUS was revised to fix a Microsoft System Center Configuration Manager reporting bug. 

Summary

An elevation of privilege vulnerability exists if the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.

To learn more about the vulnerability, go to CVE-2018-0952.

More information

Prerequisites

To apply this security update, you must have both Visual Studio 2015 Update 3 and the subsequent Cumulative Servicing Release KB 3165756 installed. Typically, KB 3165756 is installed automatically when you install Visual Studio 2015 Update 3. However, in some cases, you have to install the two packages separately.

Restart requirement

We recommend that you close Visual Studio 2015 before you install this security update. Otherwise, you may have to restart the computer after you apply this security update if a file that is being updated is open or in use by Visual Studio.

Security update replacement information

This update replaces KB4456688.

File hash information

File name

SHA1 hash

SHA256 hash

vs14-kb4463110.exe

675961AABDFA243A8FE3E8C9DB092EF577B450DF

7A44B99CD19EDBDABF27C7200FC9E5CB5615D32259BE5F969BD6740C055B623B

Installation verification

To check that this security update was applied correctly, follow these steps:

  1. Open the Visual Studio 2015 folder.

  2. Locate the DiagnosticHub.StandardCollector.Runtime.dll file.

  3. Verify that the file version is equal to or greater than 14.0.27527.

Information about protection, security, and support

Potrebna vam je dodatna pomoć?

Proširite svoje vještine
Istražite osposobljavanje
Prvi koristite nove značajke
Pridružite se Microsoft Insidere

Jesu li ove informacije bile korisne?

Hvala vam na povratnim informacijama!

Hvala vam na povratnim informacijama! Čini se da bi vam pomoglo kad bismo vas povezali s nekim od naših agenata podrške za Office.

×