CVE-2018-8532: XEE
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8532?
The severity of CVE-2018-8532 is rated as important, indicating a potential risk of information disclosure.
How do I fix CVE-2018-8532?
To fix CVE-2018-8532, users should upgrade to the latest version of Microsoft SQL Server Management Studio.
What products are affected by CVE-2018-8532?
CVE-2018-8532 affects Microsoft SQL Server Management Studio versions 17.9 and 18.0.
What kind of vulnerability is CVE-2018-8532?
CVE-2018-8532 is classified as an information disclosure vulnerability.
Can CVE-2018-8532 be exploited remotely?
Yes, CVE-2018-8532 can potentially be exploited remotely via a specially crafted XMLA file.