Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Microsoft · SQL Server
Date added (CISA)
2024-09-18
Remediation due
2024-10-09
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.