← Back to browse · API

CVE-2020-0618

Severity
CRITICAL
CVSS
9.8
EPSS
0.99022
Risk score
59.66
CISA KEV
Yes
PoC
No
Published
2020-02-11
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2020-2113, GHSA-JCVJ-VHJ2-VGMW
Products
Microsoft:Microsoft SQL Server 2012 for 32-bit Systems Service Pack 4 (QFE), Microsoft:Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE), Microsoft:Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU) unspecified, Microsoft:Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR) unspecified, Microsoft:Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU) unspecified, Microsoft:Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR) unspecified, Microsoft:Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (CU), Microsoft:Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR) unspecified, Microsoft:SQL Server
Sources
cisa.gov CVE-2020-0618
euvd EUVD-2020-2113

Description

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

References