// For flags

CVE-2020-0618

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

5
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

Act
*SSVC
Descriptions

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

Se presenta una vulnerabilidad de ejecución de código remota en Microsoft SQL Server Reporting Services cuando maneja inapropiadamente las peticiones de página, también se conoce como "Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability".

A vulnerability exists within Microsoft's SQL Server Reporting Services which can allow an attacker to craft an HTTP POST request with a serialized object to achieve remote code execution. The vulnerability is due to the fact that the serialized blob is not signed by the server.

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:Act
Exploitation
Active
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2019-11-04 CVE Reserved
  • 2020-02-11 CVE Published
  • 2020-02-15 First Exploit
  • 2024-09-18 Exploited in Wild
  • 2024-09-21 CVE Updated
  • 2024-10-09 KEV Due Date
  • 2024-10-28 EPSS Updated
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2012
Search vendor "Microsoft" for product "Sql Server" and version "2012"
sp4
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2014
Search vendor "Microsoft" for product "Sql Server" and version "2014"
sp3
Affected
Microsoft
Search vendor "Microsoft"
Sql Server
Search vendor "Microsoft" for product "Sql Server"
2016
Search vendor "Microsoft" for product "Sql Server" and version "2016"
sp2, x64
Affected