CVE-2018-8527 is an information disclosure vulnerability in Microsoft SQL Server Management Studio (SSMS) versions 17.9 and 18.0. It arises from improper parsing of malicious XEL files containing external entity references, allowing an attacker to potentially disclose sensitive information. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction, and leading to high confidentiality impact. While not actively exploited in the wild, public exploit code exists via ExploitDB, and it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.9CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_management_studio:17.9:*:*:*:*:*:*:* | ||
18.0CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_management_studio:18.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.