Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Description of the security update for the information disclosure vulnerability in Microsoft Visual Studio 2013 Update 5: July 9, 2019


View products that this article applies to.


Note This security update applies to Visual Studio 2013 Update 5 except for Visual Studio Isolated and Integrated Shells.  

↑ Back to the top


Summary

An information disclosure vulnerability exists if Microsoft Visual Studio 2013 incorrectly parses XML input in certain settings files.

To learn more about the vulnerability, go to CVE-2019-1079.
 

Known issues in this update

Symptom
Visual Studio 2013 customers may experience issues that affect the offering of this update through Microsoft Update. In some cases, this update is offered to products for which the update was not intended or needed, such as Visual Studio Isolated and Integrated Shells.

Status
On August 5, 2019, a detection revision was made to address issues that affect the Microsoft Update offering for this update. Customers who observed unexpected issues in the offering of this update can rescan Microsoft Update for the latest content within their Windows Server Update Services (WSUS) and update management environments. Customers who rely on the Wsusscan2.cab file will receive this revision as part of the August 2019 broad Windows Update releases..

↑ Back to the top


How to obtain and install the update

Method 1: Microsoft Download

The following file is available for download:

Download Download the hotfix package now.

Method 2: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog website.

↑ Back to the top


More information

Prerequisites

To apply this security update, you must have Visual Studio 2013 Update 5 installed.

Restart requirement

You may have to restart the computer after you apply this security update if an instance of Visual Studio is being used.

Security update replacement information

This security update doesn't replace other security updates.

Deployment information

For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

Security update deployment information: July 9, 2019

File hash information

File name SHA1 hash SHA256 hash
VS12-KB4506163.exe 82EA6AB14CB97EB4F37C2D46A52A921D1E2EF4DB AE62A60ADD146B35DD58E8BD7E5919BE2D0786481BF8D60E0663535A07178E61


File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

VS12-KB4506163.exe file information

↑ Back to the top


How to get help and support for this security update

Help for installing updates: Protect yourself online

Help for protecting your Windows-based computer from viruses and malware: Microsoft Security

Local support according to your country: International Support

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew, kb, kblangall

↑ Back to the top

Article Info
Article ID : 4506163
Revision : 23
Created on : 3/9/2020
Published on : 3/18/2020
Exists online : False
Views : 276