CVE-2020-0618CISA KEV
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.
- Product
- SQL Server
- Added to KEV
- 18 Sep 2024
- Federal remediation due
- 9 Oct 2024
- Known ransomware use
- Yes