← Vulnerability feed

Vulnerability record · CVE-2018-8532 · published 10 October 2018

CVE-2018-8532: Microsoft sql server management studio xml external entity (xxe) vulnerability

Microsoft · Sql Server Management Studio

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533.

5.5 CVSS 3.0 Medium EPSS 23% · top 2.3% CWE-611 · XML external entity (XXE)
5.5CVSS 3.0 base score, v2 4.3
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0. This CVE ID is unique from CVE-2018-8527, CVE-2018-8533.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8532 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.3CVE-2025-29803Microsoft sql server management studio uncontrolled search path element vulnerabilityUncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate pr…EPSS 0.75%6.5CVE-2019-1376Microsoft sql server management studio vulnerabilityAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Ser…EPSS 5.4%6.5CVE-2019-1313Microsoft sql server management studio vulnerabilityAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Ser…EPSS 5.3%5.5CVE-2018-8527Microsoft sql server management studio xml external entity (xxe) vulnerabilityAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a refere…EPSS 23%5.5CVE-2018-8533Microsoft sql server management studio xml external entity (xxe) vulnerabilityAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refer…EPSS 23%5.3CVE-2020-1455Microsoft sql server management studio vulnerabilityA denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the v…EPSS 1.2%9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2018-8532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.