An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity. This affects SQL Server Management Studio 17.9, SQL Server Management Studio 18.0.