Main
Vulnerability Database
Exploits
ID:4625 - Exploit for Input validation error in Microsoft SQL Server - CVE-2020-0618
ID:4625 - Exploit for Input validation error in Microsoft SQL Server - CVE-2020-0618
Published: September 18, 2020
Vulnerability identifier: #VU25231
Vulnerability risk: Medium
CVE-ID: CVE-2020-0618
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Microsoft SQL Server
Microsoft SQL Server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of page requests. A remote authenticated attacker can submit a specially crafted page request to the affected Reporting Services instance and execute arbitrary code on the system.
Remediation
Install updates from vendor's website.