CVE-2018-8533: XEE
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8532.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8533?
CVE-2018-8533 is rated as a moderate severity vulnerability affecting Microsoft SQL Server Management Studio.
How do I fix CVE-2018-8533?
To fix CVE-2018-8533, upgrade to the latest version of Microsoft SQL Server Management Studio that includes the security patch.
What versions of SQL Server Management Studio are affected by CVE-2018-8533?
CVE-2018-8533 affects Microsoft SQL Server Management Studio versions 17.9 and 18.0.
What type of vulnerability is CVE-2018-8533?
CVE-2018-8533 is classified as an information disclosure vulnerability related to the parsing of malicious XML.
Can CVE-2018-8533 lead to data exposure?
Yes, CVE-2018-8533 can potentially lead to data exposure through the manipulation of external entities in XML content.