CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2024-09-18. EPSS: 99% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

Affected products

  • Microsoft SQL Server: version 2012 only; version 2014 only; version 2016 only

Published 2020-02-11. Last modified 2026-08-15.