Executive brief
Microsoft SQL Server Reporting Services (SSRS) contains a deserialization vulnerability (CWE-502) when handling page requests. An authenticated attacker can exploit this to execute arbitrary code in the context of the Report Server service account.
Affected products
- Microsoft SQL Server 2012 Service Pack 4
- Microsoft SQL Server 2014 Service Pack 3
- Microsoft SQL Server 2016 Service Pack 2
Timeline
- 2020-02-11: disclosed: NVD Published Date
- 2020-02-11: patched: MSRC advisory and patch released
- 2024-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-18: exploited: Confirmed as exploited in the wild per CISA KEV entry