Information disclosure in Microsoft SQL Server Management Studio - CVE-2019-1313

 

Information disclosure in Microsoft SQL Server Management Studio - CVE-2019-1313

Published: October 9, 2019


Vulnerability identifier: #VU21659
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1313
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the affected software improperly enforces permissions. A local authenticated user with credentials allowing access to an affected SQL server database can gain additional database and file information.


Affected software

Microsoft SQL Server Management Studio

How to mitigate CVE-2019-1313

Install updates from vendor's website.

Microsoft SQL Server Management Studio - update to 18.3.1

External References

Related Security Bulletins