Get the App
SLTechnology News&Howtos  ›  Servers  › 

(CVE-2020-0618) repair of remote code execution vulnerability in sql2012

Shulou Source: shulou.com Published: 2022-06-02 10:46:48 10月02日 Update

Because sql2012 has a remote loophole, now we need to fix it. It is a project done by Party B of the company that used sql and wrangled for a long time about who is going to make a patch. Ah, Party B is now an uncle, so I found a lot of information on the Internet and wrote down the process of patching myself (I was installed in a virtual machine, because it is not sure that there is, which party will install it).

If Microsoft SQL Server Reporting Services improperly handles page requests, a remote code execution vulnerability exists. People who successfully exploit this vulnerability can execute code in the context of the report server service account. To learn more about this vulnerability, check CVE-2020-0618 for it.

Details of the official vulnerability of https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0618

The condition in the https://support.microsoft.com/zh-cn/help/4532098/security-update-for-sql-server-2012-sp4-gdr download vulnerability installation package is that to apply this update, you must install SQL Server 2012 SP4 or any version of SQL Server 2012 SP4 GDR, and use this SQL Server 2012 SP4 GDR. So we have to download sp4 to install this before we can hit this vulnerability.

Introduction to https://docs.microsoft.com/zh-cn/archive/blogs/sqlreleaseservices/sql-server-2012-service-pack-4-sp4-released sp4

Download address of https://www.microsoft.com/zh-CN/download/details.aspx?id=56040 sp4, my 64-bit

Install the sp4 package above and double-click the installation directly.

First check the version of my sql2012 as shown in the figure (this is the pre-installation version of nothing. Note that it is different each time):

SELECT @ @ VERSION # View version is executed in the new query

Double click to start installation

The next step depends on the prompt to stop several services.

Go to the service and see that this is stopped. don't worry about it.

This is also stopped.

Kill the process it's talking about first.

wait for

Finally shut down and restart the system

Install that vulnerability. Before that, let's check if there is any change in the version. There is an extra sp4.

Http://www.microsoft.com/download/details.aspx?FamilyID=b09d2a89-b1f4-4571-b3db-037389beee58 downloads vulnerable packages

Double-click to install

The process number that ends the prompt

After the update is completed, let's see how the version changes. After rebooting the system, let's see.

At this point, we completed the update patch for this vulnerability and went to bed late.

Tags: Vulnerabilities versions services patches updates codes Party B systems processes changes prompts queries success upper and lower context no information company address sir Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info Shulou Technology MySQL vpn NVidia