CVE-2020-0618 is a critical remote code execution vulnerability affecting Microsoft SQL Server Reporting Services (SSRS) due to incorrect handling of page requests. With a CVSS score of 8.8 (HIGH), it allows an unauthenticated attacker to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. This vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2012:sp4:*:*:*:*:*:* | ||
2014CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2014:sp3:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server:2016:sp2:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.