🔙 목록으로 돌아가기

CVE-2020-0618: Microsoft SQL Server Reporting Services - Remote Code Execution

TitleMicrosoft SQL Server Reporting Services - Remote Code Execution
Authorjoeldeleep
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security updates provided by Microsoft to mitigate this vulnerability.
CVSS Score8.8
EPSS Score0.94252
CVE IDCVE-2020-0618
CWE IDCWE-502
Tags cve cve2020 rce packetstorm microsoft kev vkev vuln

🔍 Vulnerability Description

Microsoft SQL Server Reporting Services is vulnerable to a remote code execution vulnerability because it incorrectly handles page requests.

🌐 HTTP Request

GET /ReportServer/Pages/ReportViewer.aspx HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-0618.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-0618.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A