Lucene search

K
mskbMicrosoftKB5025792
HistoryJun 13, 2023 - 7:00 a.m.

Description of the security update for the remote code execution vulnerability in Microsoft Visual Studio 2015 Update 3: June 13, 2023 (KB5025792)

2023-06-1307:00:00
Microsoft
support.microsoft.com
226
microsoft
visual studio 2015
security update
remote code execution
vulnerability
download
installation
verification
file information
security

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.0%

Description of the security update for the remote code execution vulnerability in Microsoft Visual Studio 2015 Update 3: June 13, 2023 (KB5025792)

**Applies to:**All Visual Studio 2015 Update 3 editions except Integrated Shell and Build Tools.

Summary

A remote code execution vulnerability exists in Microsoft Visual Studio 2015 when it incorrectly handles debug information.To learn more about the vulnerability, see CVE-2023-21808, CVE-2023-23381, CVE-2023-24897, and CVE-2023-21815.

How to obtain and install the update

Method 1: Microsoft Download

The following file is available for download:Download icon Download the hotfix package now.

Method 2: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog website.

More information

Prerequisites

To apply this security update, you must have Visual Studio 2015 Update 3 installed.

Restart requirement

We recommend that you close Visual Studio 2015 before you install this security update. Otherwise, you may have to restart the computer after you apply this security update if a file that is being updated is open or in use by Visual Studio.

Security update replacement information

This security update doesn’t replace other security updates.

File hash information

File name SHA256 hash
vs14-kb5025792.exe F2E3D08C86B769644C9CBDA08F5617BCBEBB4FEEF43B752DD37DAC2CE8395C2E

File information

File name File version File size Date Time
vs14-kb5025792.exe 14.0.27555.0 11,142,464 June β€Ž8, β€Ž2023 9:50:30 PM

Installation verification

To verify that this security update is applied correctly, follow these steps:

  1. Open the Visual Studio 2015 program folder.
  2. Locate one or more of the following files and verify that the file version is equal to or greater than the version mentioned in the table below:File| Version
    β€”|β€”
    common7\ide\msdia140.dll| 14.0.24247.3
    common7\packages\debugger\msdia140.dll| 14.0.24247.3
    dia sdk\bin\amd64\msdia140.dll| 14.0.24247.3
    dia sdk\bin\arm\msdia140.dll| 14.0.24247.3
    dia sdk\bin\msdia140.dll| 14.0.24247.3
    team tools\dynamic code coverage tools\amd64\msdia140.dll| 14.0.24247.3
    team tools\dynamic code coverage tools\msdia140.dll| 14.0.24247.3
    team tools\performance tools\x64\msdia140.dll| 14.0.24247.3
    vc\bin\1033\mspdbcmfui.dll| 14.0.24247.3
    vc\bin\amd64\1033\mspdbcmfui.dll| 14.0.24247.3
    vc\bin\amd64\bscmake.exe| 14.0.24247.3
    vc\bin\amd64\msobj140.dll| 14.0.24247.3
    vc\bin\amd64\mspdb140.dll| 14.0.24247.3
    vc\bin\amd64\mspdbcmf.exe| 14.0.24247.3
    vc\bin\amd64\mspdbcore.dll| 14.0.24247.3
    vc\bin\amd64\mspdbsrv.exe| 14.0.24247.3
    vc\bin\amd64\mspdbst.dll| 14.0.24247.3
    vc\bin\bscmake.exe| 14.0.24247.3
    vc\bin\msobj140.dll| 14.0.24247.3
    vc\bin\mspdb140.dll| 14.0.24247.3
    vc\bin\mspdbcmf.exe| 14.0.24247.3
    vc\bin\mspdbcore.dll| 14.0.24247.3
    vc\bin\mspdbsrv.exe| 14.0.24247.3
    vc\bin\mspdbst.dll| 14.0.24247.3
    Team Tools\Dynamic Code Coverage Tools\covrun32.dll| 14.0.27555.0
    Team Tools\Dynamic Code Coverage Tools\amd64\covrun64.dll| 14.0.27555.0

Information about protection and security

Protect yourself online: Windows Security supportLearn how we guard against cyber threats: Microsoft Security

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.0%