#VU14918 Input validation error in Microsoft SQL Server Management Studio - CVE-2018-8527
Published: September 27, 2018 / Updated: June 17, 2021
Microsoft SQL Server Management Studio
Microsoft
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to unspecified error when processing XEL files. A local user with privileges to read data on SQL server can gain unauthorized access to sensitive information stored in database and on the filesystem.
Note: this vulnerability seems to be unintentionally disclosed by Microsoft before the official patch release.