CVE-2020-1044: Microsoft SQL Server Reporting Services

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

<p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an administrator.</p> <p>To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected SSRS server.</p> <p>The update addresses the vulnerability by modifying how SSRS validates attachment uploads.</p>

Affected products

  • Microsoft SQL Server Reporting Services: version 2017 only; version 2019 only

Published 2020-09-11. Last modified 2026-06-17.