CVE-2020-0618
HIGH KEV RANSOMWARE NUCLEIMicrosoft Sql Server - Insecure Deserialization
Title source: ruleDescription
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Exploits (6)
exploitdb
WORKING POC
by West Shepherd · pythonremotewindows
https://www.exploit-db.com/exploits/48816
metasploit
WORKING POC
EXCELLENT
by Soroush Dalili, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/ssrs_navcorrector_viewstate.rb
Nuclei Templates (1)
Microsoft SQL Server Reporting Services - Remote Code Execution
HIGHby joeldeleep
References (4)
Scores
CVSS v3
8.8
EPSS
0.9425
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
no
Technical Impact
total
Details
CISA KEV
2024-09-18
VulnCheck KEV
2023-06-05
InTheWild.io
2024-09-18
ENISA EUVD
EUVD-2020-2113
Ransomware Use
Confirmed
CWE
CWE-502
Status
published
Products (3)
microsoft/sql_server
2012 sp4
microsoft/sql_server
2014 sp3
microsoft/sql_server
2016 sp2
Published
Feb 11, 2020
KEV Added
Sep 18, 2024
Tracked Since
Feb 18, 2026