CVE-2020-0618
KEV · ransomware High · CVSS 8.8- CVSS
- 8.8
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- other
- CWE-502, CWE-502
Description
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
References
- http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.html
- http://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
- http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.html
- http://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0618
Status: profiled · ingested 2026-08-15T06:00:50.000Z