An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the current channel channel.Update Microsoft Visual Studio 2015 to the latest version in the LTSC 14.0 version stream, or upgrade to a newer supported version of Visual Studio 2015.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017. | Jun 25, 2025 | Aug 14, 2018 |
| Msft | — | 2018-08 Cumulative Update for Microsoft Windows 10, version 1803 (KB4343909)2018-08 Cumulative Update for Microsoft Windows Server 2016, version 1607 (KB4343887)2018-08 Cumulative Update for Microsoft Windows 10, version 1607 (KB4343887)2018-08 Cumulative Update for Microsoft Windows 10, version 1709 (KB4343897)2018-08 Cumulative Update for Microsoft Windows 10, version 1703 (KB4343885)2018-08 Cumulative Update for Microsoft Windows 10, version 1507 (KB4343892) | Aug 14, 2018 | Aug 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub