← Vulnerability feed

Vulnerability record · CVE-2020-0618 · published 11 February 2020

CVE-2020-0618: Microsoft SQL Server Reporting Services ViewState deserialization RCE

Microsoft · Sql Server

SQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can send crafted requests to the SSRS endpoint and execute code in the service context, which is why this carries a CVSS 3.1 base score of 8.8 and is listed in CISA KEV.

8.8 CVSS 3.1 High CISA KEV since 18 Sep 2024 Known ransomware use EPSS 99% · top 0.1% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 6.5
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
15 Aug 2026Last modified by NVD

Description

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a 99.9th percentile EPSS score, public exploit code, and yields remote code execution with high impact.

What it is

SQL Server Reporting Services mishandles page requests, allowing untrusted ViewState data to be deserialized (CWE-502). An authenticated attacker can send crafted requests to the SSRS endpoint and execute code in the service context, which is why this carries a CVSS 3.1 base score of 8.8 and is listed in CISA KEV.

Impact

Successful exploitation gives the attacker remote code execution on the SSRS host, with high impact to confidentiality, integrity and availability. Because SSRS often runs with elevated service privileges, compromise can extend to the underlying SQL Server and connected data.

Attack surface

Reachable over the network via the SSRS web endpoint (AV:N, AC:L). The vector requires low privileges (PR:L) and no user interaction (UI:N), so any authenticated account able to reach the reporting service is enough.

Exploitation

CISA added it to KEV on 2024-09-18 with a 2024-10-09 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99022 (99.9th percentile). Public exploit code is referenced by Packet Storm advisories, so exploitation is both practical and observed.

What to do

  • Apply the Microsoft security update for CVE-2020-0618 (portal.msrc.microsoft.com advisory) to all affected SQL Server Reporting Services instances.
  • If patching is not immediately possible, follow CISA's required action: apply vendor mitigations or discontinue use of the product.
  • Restrict network access to SSRS endpoints to trusted hosts and require strong authentication; do not expose the reporting service to the internet.
  • Run the SSRS service account with least privilege and isolate it from high-value SQL Server and domain resources.
  • Inventory all SSRS deployments, including legacy SQL Server 2016-era installs, so none are missed during remediation.

Detection

  • Monitor SSRS web logs and IIS logs for anomalous POST requests to reporting endpoints, especially those with unusually large or malformed ViewState parameters.
  • Alert on unexpected child processes spawned by the SSRS service (ReportingServicesService.exe), such as cmd.exe, powershell.exe or w3wp.exe children.
  • Hunt for outbound connections or file writes originating from the SSRS host that do not match normal reporting traffic.
  • Correlate authentication events against SSRS access to spot low-privileged accounts issuing unusual page requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-0618 to the Known Exploited Vulnerabilities catalog on 18 September 2024 as "Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-0618 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed10.0CVE-2002-1145Microsoft data engine vulnerabilityThe xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft D…EPSS 8.3%10.0CVE-2002-0721Microsoft SQL Server weak permissions on extended stored proceduresMicrosoft SQL Server 7.0 and 2000 installs extended stored procedures tied to helper functions with weak permissions. Unprivileged users, and possibl…EPSS 46%analysed9.8CVE-2018-8273Microsoft sql server out-of-bounds write vulnerabilityA buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…EPSS 29%9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%9.3CVE-2009-2501Microsoft windows 2003 server memory buffer overflow vulnerabilityHeap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Offic…EPSS 27%9.3CVE-2009-2503Microsoft windows 2003 server code injection vulnerabilityGDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office Sys…EPSS 22%

Source: NIST National Vulnerability Database (record CVE-2020-0618), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.