CVE-2020-0618
KEV ransomware PoC ×2largeAuthenticated deserialization RCE in Microsoft SQL Server Reporting Services
CISA: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
CVE-2020-0618 is a remote code execution flaw in Microsoft SQL Server Reporting Services (SSRS) caused by unsafe deserialization (CWE-502) of page-request/ViewState data submitted to a report server. An attacker with low-privilege (authenticated) access to a vulnerable SSRS instance can send a crafted serialized payload in a page request, with no user interaction, causing the server to deserialize attacker-controlled data and execute code. Successful exploitation yields remote code execution in the context of the SSRS service account, which is often highly privileged, enabling server compromise and lateral movement. Any organization running affected on-premises Microsoft SQL Server Reporting Services deployments is in scope. The flaw was patched in Microsoft's February 2020 Patch Tuesday, public PoCs have circulated since 2020, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-18 with known ransomware use and a near-certain EPSS score (99.0%), so exploitation in the wild is confirmed.
What to do: Apply the SQL Server/SSRS security updates released in Microsoft's February 2020 Patch Tuesday (or subsequent cumulative updates) per Microsoft's guidance, satisfying CISA's KEV required action. Inventory environments for SSRS deployments — prioritizing internet-facing report servers — and hunt for evidence of exploitation given the known ransomware use. Restrict network access to report servers and confirm the SSRS service account is not over-privileged to limit impact if exploited.
| Microsoft SQL Server Reporting Services (SSRS) | Affected on-premises SQL Server Reporting Services builds as patched in the February 2020 Patch Tuesday updates; public PoC demonstrated against SQL Server Repo |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
- Affected
- Microsoft SQL Server
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- sql server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H