Image

SQL Server Management Studio — Known Vulnerabilities

7 vulnerabilities mapped against this product across all versions. Grouped by the release each fix landed in — newest tracked release v21.6.17.
Fixed in v20.x 1
CVE-2025-29803 Fixed in 20.2.1 CVSS 7.3 · High NVD ↗ Apr 12, 2025
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Fixed in v18.x 6
CVE-2019-1376 Affects 18.3.1–18.3.1 CVSS 6.5 · Medium NVD ↗ Oct 10, 2019
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313.
CVE-2019-1313 Affects 18.3–18.3.1 CVSS 6.5 · Medium NVD ↗ Oct 10, 2019
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376.
CVE-2018-8527 Affects 17.9–18.0 CVSS 5.5 · Medium NVD ↗ Oct 10, 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management…
CVE-2018-8532 Affects 17.9–18.0 CVSS 5.5 · Medium NVD ↗ Oct 10, 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management…
CVE-2018-8533 Affects 17.9–18.0 CVSS 5.5 · Medium NVD ↗ Oct 10, 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio…
CVE-2020-1455 Fixed in 18.6 CVSS 5.3 · Medium NVD ↗ Aug 17, 2020
A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require execution…
Source: NVD · CISA KEV · data as of Jun 8, 2026