CVE-2018-8532 EXPLOIT
5.5
MEDIUM · CVSS 3.0 · EPSS 23.4% (pctl 98)
Patch early
A public exploit exists.
Description
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533.
Scoring
| CVSS | 5.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| EPSS | 23.37% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-10-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | sql server management studio |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection | 2018-10-11 |
References
- http://www.securityfocus.com/bid/105475
- http://www.securitytracker.com/id/1041826
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8532
- https://www.exploit-db.com/exploits/45587/
- http://www.securityfocus.com/bid/105475
- http://www.securitytracker.com/id/1041826
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8532
- https://www.exploit-db.com/exploits/45587/
→ the Explorer · watch your stack · NVD