ZeroHour

CVE-2020-0618

KEV ransomware PoC ×2large

Authenticated deserialization RCE in Microsoft SQL Server Reporting Services

CISA: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2020-0618 is a remote code execution flaw in Microsoft SQL Server Reporting Services (SSRS) caused by unsafe deserialization (CWE-502) of page-request/ViewState data submitted to a report server. An attacker with low-privilege (authenticated) access to a vulnerable SSRS instance can send a crafted serialized payload in a page request, with no user interaction, causing the server to deserialize attacker-controlled data and execute code. Successful exploitation yields remote code execution in the context of the SSRS service account, which is often highly privileged, enabling server compromise and lateral movement. Any organization running affected on-premises Microsoft SQL Server Reporting Services deployments is in scope. The flaw was patched in Microsoft's February 2020 Patch Tuesday, public PoCs have circulated since 2020, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-18 with known ransomware use and a near-certain EPSS score (99.0%), so exploitation in the wild is confirmed.

What to do: Apply the SQL Server/SSRS security updates released in Microsoft's February 2020 Patch Tuesday (or subsequent cumulative updates) per Microsoft's guidance, satisfying CISA's KEV required action. Inventory environments for SSRS deployments — prioritizing internet-facing report servers — and hunt for evidence of exploitation given the known ransomware use. Restrict network access to report servers and confirm the SSRS service account is not over-privileged to limit impact if exploited.

Affected
Microsoft SQL Server Reporting Services (SSRS)Affected on-premises SQL Server Reporting Services builds as patched in the February 2020 Patch Tuesday updates; public PoC demonstrated against SQL Server Repo
Estimated exposure
large≈100,000–1,000,000 SSRS deployments, of which likely tens of thousands are internet-exposed — SSRS ships as an integrated component of on-premises Microsoft SQL Server, one of the most widely deployed enterprise databases, and is commonly enabled on report servers, so a sizable share of the very large SQL Server install base —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft SQL Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
sql server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news