Junglewise Threat Intelligence

CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

CVE-2020-0618 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-09-18

Executive brief

Microsoft SQL Server Reporting Services (SSRS) contains a deserialization vulnerability (CWE-502) when handling page requests. An authenticated attacker can exploit this to execute arbitrary code in the context of the Report Server service account.

Affected products

  • Microsoft SQL Server 2012 Service Pack 4
  • Microsoft SQL Server 2014 Service Pack 3
  • Microsoft SQL Server 2016 Service Pack 2

Timeline

  • 2020-02-11: disclosed: NVD Published Date
  • 2020-02-11: patched: MSRC advisory and patch released
  • 2024-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-18: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats