Information Disclosure Vulnerability in Microsoft SQL Server Management Studio
CVE-2018-8533
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 October 2018
Summary
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) due to improper parsing of malicious XML content that contains references to external entities. This flaw can enable an attacker to potentially retrieve sensitive information from the server. Affected versions include SQL Server Management Studio 17.9 and 18.0. Users should ensure proper updates and patching to mitigate risks associated with this vulnerability.
Affected Version(s)
SQL Server Management Studio 17.9 SQL Server Management Studio 17.9
SQL Server Management Studio 18.0 (Preview 4)
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved