Microsoft SQL Server Reporting Services RCE Vulnerability PoC is available
SQL Server Reporting Services is a server-based report generating software system from Microsoft. It is part of a suite of Microsoft SQL Server services, including SSAS and SSIS. Administered via a Web interface, it can be used to prepare and deliver a variety of interactive and printed reports.
Vulnerability Detail
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests. An attacker who successfully exploited this vulnerability could execute code in the context of the Report Server service account.
To exploit the vulnerability, an authenticated attacker would need to submit a specially crafted page request to an affected Reporting Services instance.
Affected version
- Microsoft SQL Server 2012 Service Pack 4(QFE)
- Microsoft SQL Server 2014 Service Pack 3(CU)
- Microsoft SQL Server 2014 Service Pack 3(GDR)
- Microsoft SQL Server 2016 Service Pack 2 (CU)
- Microsoft SQL Server 2016 Service Pack 2 (GDR)