FAIL › dossier
SQL Server
PRODUCT· dossier confidence 90%
SQL Server is a Microsoft relational database product with a documented history of high-severity remote code execution vulnerabilities in both the core engine and Reporting Services, indicating systemic issues with deserialization and unpatched edge components.
PROFILE
CategorydatabaseWhat they doSQL Server is a relational database management system developed by Microsoft.
SECURITY POSTURE
The product has a documented history of high-severity remote code execution vulnerabilities in both the core engine and Reporting Services, indicating systemic issues with deserialization and unpatched edge components.
Notable failures
- CVE-2019-1068 RCE in unpatched engine
- CVE-2020-0618 RCE in Reporting Services
Patterns: repeated unpatched RCEs in core and reporting components
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-08-26 | CVE-2019-1068 | high | An unpatched remote code execution flaw in Microsoft SQL Server allowed attackers to execute arbitrary code as the database engine service account. |
| 2024-09-18 | CVE-2020-0618 | high | Microsoft SQL Server Reporting Services exploited a deserialization RCE vulnerability (CVE-2020-0618) allowing authenticated attackers to execute code as the service account. |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-27 04:03:00.049176+00:00