A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HMicrosoft SQL Server
APPMicrosoft201220142016
CISA KEV — szczegółyi
- Dostawcai
- Microsoft ↗
- Produkti
- SQL Server
- Data dodania do KEVi
- 18 września 2024
- Termin remediation (USA)i
- 9 października 2024(po terminie)
- Ransomwarei
- Aktywne kampanie ransomware używają tej podatności
Zastosuj mitygacje zgodnie z instrukcjami producenta lub zaprzestań użytkowania produktu, jeśli mitygacje są niedostępne.
▸ Pokaż oryginał (EN)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Microsoft SQL Server Reporting Services zawiera podatność deserializacji przy nieprawidłowym obsługiwaniu żądań stron. Uwierzytelniony atakujący może wykorzystać tę podatność do wykonania kodu w kontekście konta usługi Report Server.
▸ Pokaż oryginał (EN)
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.
Powiązane podatności
Buffer overflow umożliwiający RCE w Microsoft SQL Server
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of...
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 ...
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Microsoft SQL OLE DB Remote Code Execution Vulnerability