Exploited Vulnerabilities Daily
🌐 English

Home › Microsoft

CVE-2020-0618: Microsoft SQL Server

EPSS99.0%No. 220 of 1739 in KEV
CVE year2020~4 yrs before listing
Same vendor in KEV389
Same product2
FieldValue
VendorMicrosoft
ProductSQL Server
NameMicrosoft SQL Server Reporting Services Remote Code Execution Vulnerability
Added to KEV2024-09-18
US federal due date2024-10-09
Ransomware useKnown
CWECWE-502

CISA description

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2019-1068Microsoft SQL Server2026-08-2657.2%Unknown

NVD — CVE-2020-0618

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Microsoft SQL Server vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-18.