#VU25231 Input validation error in Microsoft SQL Server - CVE-2020-0618
Published: February 11, 2020 / Updated: September 18, 2024
Microsoft SQL Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of page requests. A remote authenticated attacker can submit a specially crafted page request to the affected Reporting Services instance and execute arbitrary code on the system.