Vulnerability Intelligence Report
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:99.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502 Deserialization of Untrusted Data
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Microsoft | Microsoft SQL Server | 2012 for 32-bit Systems Service Pack 4 (QFE) (affected), 2012 for x64-based Systems Service Pack 4 (QFE) (affected), 2016 for x64-based Systems Service Pack 2 (CU) (affected) |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR) | unspecified (affected) |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU) | unspecified (affected) |
| Microsoft | Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR) | unspecified (affected) |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR) | unspecified (affected) |
| Microsoft | Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU) | unspecified (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.022%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Microsoft Corporation · Vendor · USA |
| Reserved | 2019-11-04T00:00:00 |
| Published | 2020-02-11T21:22:45 |
| Last Updated | 2026-08-15T03:55:30 |
Community Chatter & Buzz