First published: Thu Oct 10 2019(Updated: )
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server Management Studio | =18.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1376 is rated as important in severity due to the potential for information disclosure.
To fix CVE-2019-1376, upgrade to a later version of Microsoft SQL Server Management Studio that addresses this vulnerability.
CVE-2019-1376 is an information disclosure vulnerability that arises from improper enforcement of permissions.
Microsoft SQL Server Management Studio version 18.3.1 is affected by CVE-2019-1376.
Yes, CVE-2019-1376 can be exploited remotely, allowing attackers to gain unauthorized access to sensitive information.