Information Disclosure Vulnerability in Microsoft SQL Server Management Studio
CVE-2018-8533

5.5MEDIUM

Key Information:

Summary

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) due to improper parsing of malicious XML content that contains references to external entities. This flaw can enable an attacker to potentially retrieve sensitive information from the server. Affected versions include SQL Server Management Studio 17.9 and 18.0. Users should ensure proper updates and patching to mitigate risks associated with this vulnerability.

Affected Version(s)

SQL Server Management Studio 17.9 SQL Server Management Studio 17.9

SQL Server Management Studio 18.0 (Preview 4)

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.