CVE-2020-0618
HIGH KEV RANSOMWARE NUCLEIMicrosoft Sql Server - Insecure Deserialization
Title source: ruleDescription
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Exploits (6)
exploitdb
WORKING POC
by West Shepherd · pythonremotewindows
https://www.exploit-db.com/exploits/48816
metasploit
WORKING POC
EXCELLENT
by Soroush Dalili, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/ssrs_navcorrector_viewstate.rb
Nuclei Templates (1)
Microsoft SQL Server Reporting Services - Remote Code Execution
HIGHby joeldeleep
References (4)
Scores
CVSS v3
8.8
EPSS
0.9425
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2024-09-18
VulnCheck KEV
2023-06-05
InTheWild.io
2024-09-18
ENISA EUVD
EUVD-2020-2113
Ransomware Use
Confirmed
Classification
CWE
CWE-502
Status
published
Affected Products (3)
microsoft/sql_server
microsoft/sql_server
microsoft/sql_server
Timeline
Published
Feb 11, 2020
KEV Added
Sep 18, 2024
Tracked Since
Feb 18, 2026