CVE-2020-0618General(microsoft / sql_server)

LOWCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft sql_server systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-09. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sql_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-30); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
sql_server

3 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-11: 1Mentions · 2026-08-15: 1Active Exploitation · 2026-08-15: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-11: 103-3003-3104-1108-15
Signal classification2 categories
General
375.0%
Active Exploitation
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-301
General1
2026-03-311
General1
2026-04-111
General1
2026-08-151
Active Exploitation1
Full discourse4 posts
  • kokumօtօ@__kokumoto
    Active Exploitation

    10件の脆弱性でランサムウェアによる悪用が確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。対象は以下。 - CVE-2025-60710 (Windows) - CVE-2020-29574 (CyberoamOS) - CVE-2020-0618 (SQL Server) - CVE-2021-4034 (polkit) - CVE-2016-0189 (IE) - CVE-2022-21882 (Windows) - CVE-2019-5591 (FortiOS) - CVE-2019-0803 (Windows) - CVE-2018-0802 (Office) - CVE-2020-0968 (IE)

    Post summary

    The text reports that CISA has confirmed ransomware exploitation of ten CVEs, without providing patches, PoCs, or technical details.

    01121102.7K
    7.8K followersView on X
  • Altay@Siber_Altay
    General

    Bu haftaki takım içi sunumlarımızda: 🛡 "CVE-2020-0618 SQL Server Zaafiyetinin İncelenmesi" gerçekleştirildi. Sunumu gerçekleştiren takım arkadaşımız alperen akca ’ ya teşekkür ederiz. https://t.co/M3kllrI2TG

    Post summary

    The post announces an internal team presentation that examined CVE-2020-0618, a SQL Server vulnerability, but it does not provide any proof‑of‑concept, exploit code, or patch information.

    0000066
    45 followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2020-0618 (EPSS 94.00%) Microsoft SQL Server Reporting Services RCE vulnerability when it incorrectly handles page requests. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2020-0618 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post cites CVE-2020-0618 with a high EPSS score and mentions its RCE nature, but it offers no PoC, active exploitation reports, patch information, or false‑positive claims.

    0000043
    311 followersView on X
  • Patrick Roland@DeusLogica
    General

    Timestamp: 2026-03-30T11:11:47.242490 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2020-0618 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2020-0618 (EPSS 94.00%) A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2020-0618 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    The post emphasizes the high EPSS score for CVE‑2020‑0618 and outlines the remote code execution flaw in SSRS, yet it provides no PoC, exploit code, or patch details.

    0000055
    307 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsql_server2012--
Appmicrosoftsql_server2014--
Appmicrosoftsql_server2016-x64

Explore more