CVE-2019-1376 is an information disclosure vulnerability in Microsoft SQL Server Management Studio (SSMS) caused by improper permission enforcement. This flaw allows an authenticated attacker to access sensitive information. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low attack complexity and does not require user interaction, leading to high confidentiality impact. While the vulnerability has a moderate FAUCET Risk Score of 61/100, it is not listed in CISA's KEV catalog and there is no public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.3.1CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_management_studio:18.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.