Vulnerability Details CVE-2020-1455
A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service.
To exploit the vulnerability, an attacker would first require execution on the victim system.
The security update addresses the vulnerability by ensuring Microsoft SQL Server Management Studio properly handles files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.3%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 2.1
Products affected by CVE-2020-1455
-
cpe:2.3:a:microsoft:sql_server_management_studio:16.5.3
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.0
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.1
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.2
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.3
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.4
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.5
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.6
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.7
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.8.1
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.9
-
cpe:2.3:a:microsoft:sql_server_management_studio:17.9.1
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.0
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.1
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.2
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.3
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.3.1
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.4
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.5
-
cpe:2.3:a:microsoft:sql_server_management_studio:18.5.1