Umbra Wiki cve cve/CVE-2020-0618
Back to wiki

CVE-2020-0618 — Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2020-0618

CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product SQL Server
Date added 2024-09-18
Due date 2024-10-09
Ransomware campaign use Known

Description

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2020-0618 ; https://nvd.nist.gov/vuln/detail/CVE-2020-0618

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-0618
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog