Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Description of the security update for the information disclosure vulnerability in Visual Studio 2013 Update 5: April 10, 2018


View products that this article applies to.

↑ Back to the top


Summary

An information disclosure vulnerability exists if Visual Studio incorrectly discloses the contents of its memory. An attacker who exploits the vulnerability could view uninitialized memory from the computer that is used to compile a program database file.

To learn more about the vulnerability, see CVE-2018-1037.

↑ Back to the top


How to obtain and install the update

Method 1: Microsoft Download

The following file is available for download:

Download Download the hotfix package now.

Method 2: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog website.

↑ Back to the top


More information

Prerequisites

To apply this security update, you must have Visual Studio 2013 Update 5 installed.

Restart requirement

You may have to restart the computer after you apply this security update if an instance of Visual Studio is being used.

Security update replacement information

This security update doesn't replace other security updates.

Issues that are fixed in this security update

This hotfix addresses the PDB security issue described in CVE-2018-1037, in which PDB files may contain uninitialized heap content in a process that updates an existing PDB file, like mspdbsrv.exe. We strongly recommend that you use the updated PDBCopy tool to check every existing PDB that you intend to share or distribute.

How to obtain help and support for this security update
Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure
Local support according to your country: International Support

↑ Back to the top


File information

File hash information
File name SHA1 hash SHA256 hash
VS12-KB4089283.exe E71CD96A75B25B84A20888277B41A0ED4550ECEB 143ED55085C46F421750917AC368CCF15099CAF9FE77EEB83EE4BC0D47A8DF2B

 

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew, kb, kblangall

↑ Back to the top

Article Info
Article ID : 4089283
Revision : 26
Created on : 3/9/2020
Published on : 3/18/2020
Exists online : False
Views : 231