An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability." This affects Microsoft Visual Studio, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.0 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2015 to the latest version in the LTSC 14.0 version stream, or upgrade to a newer supported version of Visual Studio 2015. | Jun 25, 2025 | Dec 11, 2018 |
| Msft | — | 2018-12 Cumulative Update for Microsoft Windows 10, version 1607 (KB4471321)2018-12 Cumulative Update for Microsoft Windows 10, version 1703 (KB4471327)2018-12 Cumulative Update for Microsoft Windows 10, version 1803 (KB4471324)2018-12 Cumulative Update for Microsoft Windows Server 2019, version 1809 (KB4471332)2018-12 Cumulative Update for Microsoft Windows Server 2016, version 1607 (KB4471321)2018-12 Cumulative Update for Microsoft Windows 10, version 1507 (KB4471323)2018-12 Cumulative Update for Microsoft Windows 10, version 1709 (KB4471329)2018-12 Cumulative Update for Microsoft Windows 10, version 1809 (KB4471332) | Dec 11, 2018 | Dec 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub