Skip to content
COOEY

FAIL › dossier

SQL Server

PRODUCT

· dossier confidence 90%

SQL Server is a Microsoft relational database product with a documented history of high-severity remote code execution vulnerabilities in both the core engine and Reporting Services, indicating systemic issues with deserialization and unpatched edge components.

PROFILE
CategorydatabaseWhat they doSQL Server is a relational database management system developed by Microsoft.
SECURITY POSTURE

The product has a documented history of high-severity remote code execution vulnerabilities in both the core engine and Reporting Services, indicating systemic issues with deserialization and unpatched edge components.

Notable failures
  • CVE-2019-1068 RCE in unpatched engine
  • CVE-2020-0618 RCE in Reporting Services
Patterns: repeated unpatched RCEs in core and reporting components
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2026-08-26 CVE-2019-1068 high An unpatched remote code execution flaw in Microsoft SQL Server allowed attackers to execute arbitrary code as the database engine service account.
2024-09-18 CVE-2020-0618 high Microsoft SQL Server Reporting Services exploited a deserialization RCE vulnerability (CVE-2020-0618) allowing authenticated attackers to execute code as the service account.
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:03:00.049176+00:00