CVE-2018-8533
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 23%
from disclosure to weapon1 days
Published on NVDOct 10
1st PoC+1d
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8532.
Affected products
Microsoft · SQL Server Management Studio 17.9Microsoft · SQL Server Management Studio 18.0public PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45583cve_referencewww.exploit-db.com/exploits/45583/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.