Input validation error in Microsoft SQL Server - CVE-2020-0618
Published: February 11, 2020 / Updated: September 18, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of page requests. A remote authenticated attacker can submit a specially crafted page request to the affected Reporting Services instance and execute arbitrary code on the system.
Affected software
How to mitigate CVE-2020-0618
Links to Public Exploits and PoC-codes
- Exploit #4625 - Microsoft SQL Server Reporting Services 2016 - Remote Code Execution (September 18, 2020)
- Exploit #2846 - CVE-2020-0618 (SQL Server Reporting Services(CVE-2020-0618)中的RCE) (June 3, 2020)
- Exploit #318 - cve-2020-0618 (CVE-2020-0618 Honeypot) (March 18, 2020)
- Exploit #1469 - SQL Server Reporting Services (SSRS) ViewState Deserialization (March 18, 2020)