VDB
GSD-2020-0618
GSD-2020-0618
PUBLISHED
CVSS 9.800000190734863 CRITICAL
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR) | unspecified |
| Microsoft | Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR) | unspecified |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU) | * |
| Microsoft | Microsoft SQL Server | 2012 for 32-bit Systems Service Pack 4 (QFE), 2012 for x64-based Systems Service Pack 4 (QFE), * |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU) | unspecified |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR) | unspecified |
Timeline
- Feb 11, 2020 CVE Published
- Mar 12, 2020 PoC Published
- Jan 15, 2021 PoC Published
- Sep 23, 2021 PoC Published
- Sep 20, 2024 PoC Published
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Feb 2, 2026 PoC Published
- Apr 16, 2026 Security Advisory
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618 advisory
- http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.html exploit
- http://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.html exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0618 advisory