CVE-2018-8527: XEE
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8532, CVE-2018-8533.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8527?
CVE-2018-8527 is rated as a medium severity vulnerability.
How do I fix CVE-2018-8527?
To fix CVE-2018-8527, update Microsoft SQL Server Management Studio to the latest version available.
What type of vulnerability is CVE-2018-8527?
CVE-2018-8527 is classified as an information disclosure vulnerability.
Which versions of SQL Server Management Studio are affected by CVE-2018-8527?
CVE-2018-8527 affects Microsoft SQL Server Management Studio versions 17.9 and 18.0.
What does CVE-2018-8527 allow an attacker to do?
CVE-2018-8527 may allow an attacker to disclose sensitive information by parsing a malicious XEL file.