HTTP: Microsoft SQL Server Reporting Services Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Microsoft SQL Server Reporting Services. A successful attack can lead to arbitrary code execution.

Extended Description

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

Affected Products

Microsoft sql_server

References

CVE: CVE-2020-0618

Short Name
HTTP:CTS:MS-SQL-SERVER-RS-RCE
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-0618 Code Execution Microsoft Remote Reporting SQL Server Services
Release Date
06/23/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3501
False Positive
Unknown
Vendors

Microsoft

CVSS Score

6.5

Found a potential security threat?