CVE-2018-8527
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8532, CVE-2018-8533.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 23.37% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- microsoft/sql server management studio
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105474Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041826Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8527Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/45585/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105474Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041826Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8527Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/45585/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.