In a recent Microsoft patch, a fix was announced for 2020-0618 which allowed low-level authorized users to remotely execute code on Microsoft SQL servers. Using the functionality provided by the SQL Server Reporting Services web application, browser level users can trigger this exploit by sending a specially crafted POST request to “/ReportServer/pages/ReportViewer.aspx.” A proof of concept (POC) exploit for this vulnerability has been released, making this a higher priority to patch.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security