Information Disclosure Vulnerability in Microsoft SQL Server Management Studio
CVE-2018-8533
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 October 2018
What is CVE-2018-8533?
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) due to improper parsing of malicious XML content that contains references to external entities. This flaw can enable an attacker to potentially retrieve sensitive information from the server. Affected versions include SQL Server Management Studio 17.9 and 18.0. Users should ensure proper updates and patching to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SQL Server Management Studio 17.9 SQL Server Management Studio 17.9
SQL Server Management Studio 18.0 (Preview 4)
References
EPSS Score
54% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved