CVE-2018-8533 is an information disclosure vulnerability in Microsoft SQL Server Management Studio (SSMS) versions 17.9 and 18.0, stemming from improper parsing of malicious XML content with external entity references. This medium-severity vulnerability has a CVSS score of 5.5, indicating that an attacker could achieve high confidentiality impact with low attack complexity, requiring user interaction. While not on CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered notable community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.9CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_management_studio:17.9:*:*:*:*:*:*:* | ||
18.0CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_management_studio:18.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.