CVE-2018-8532 Information

Description

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity aka \SQL Server Management Studio Information Disclosure Vulnerability.\ This affects SQL Server Management Studio 17.9 SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527 CVE-2018-8533.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Reference

http://www.securityfocus.com/bid/105475 http://www.securitytracker.com/id/1041826 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8532 https://www.exploit-db.com/exploits/45587/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

5.5

Share on: