A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2020-0618

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Published
2024-09-18
Modified
2026-07-31
Sources
cisa-kev

Summary

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.