V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-8527
CVE
MediumConfirmedExploit available

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containin…

CVSS
5.5
Medium
EPSS
0.48
p97
Published
2018-01-01
Updated
2018-01-01
Description

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8532, CVE-2018-8533.

Tags · CWE
CWE-611
CAPEC-221
Affected products
Sql_server_management_studio
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.478 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
45585
exploitdb · https://www.exploit-db.com/exploits/45585
Enterprise
Affected software
ProductVendorStatus
sql_server_management_studio*Tracked
Source databases
CVE
Related vulnerabilities