Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0056


Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability


Published

2024-01-09T18:15:46.783

Last Modified

2024-11-21T08:45:49.180

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.7 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-319
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft microsoft.data.sqlclient < 2.1.7 Yes
Application microsoft microsoft.data.sqlclient < 3.1.5 Yes
Application microsoft microsoft.data.sqlclient < 4.0.5 Yes
Application microsoft microsoft.data.sqlclient < 5.1.3 Yes
Application microsoft sql_server 2022 Yes
Application microsoft sql_server 2022 Yes
Application microsoft system.data.sqlclient < 4.8.6 Yes
Application microsoft visual_studio_2022 < 17.2.23 Yes
Application microsoft visual_studio_2022 < 17.4.15 Yes
Application microsoft visual_studio_2022 < 17.6.11 Yes
Application microsoft visual_studio_2022 < 17.8.4 Yes
Application microsoft .net_framework < 4.8.04690.02 Yes
Operating System microsoft windows_10_1607 - No
Operating System microsoft windows_10_1607 - No
Operating System microsoft windows_server_2008 r2 No
Operating System microsoft windows_server_2012 - No
Operating System microsoft windows_server_2012 r2 No
Operating System microsoft windows_server_2016 - No
Application microsoft .net_framework < 4.8.04690.01 Yes
Operating System microsoft windows_server_2008 r2 No
Application microsoft .net_framework 4.6.2 Yes
Application microsoft .net_framework 4.7 Yes
Application microsoft .net_framework 4.7.1 Yes
Application microsoft .net_framework 4.7.2 Yes
Operating System microsoft windows_server_2008 r2 No
Operating System microsoft windows_server_2012 - No
Operating System microsoft windows_server_2012 r2 No
Application microsoft .net_framework 3.5 Yes
Application microsoft .net_framework 4.8.1 Yes
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_10_21h2 - No
Operating System microsoft windows_10_21h2 - No
Operating System microsoft windows_10_21h2 - No
Operating System microsoft windows_10_22h2 - No
Operating System microsoft windows_10_22h2 - No
Operating System microsoft windows_10_22h2 - No
Operating System microsoft windows_11_21h2 - No
Operating System microsoft windows_11_21h2 - No
Operating System microsoft windows_11_22h2 - No
Operating System microsoft windows_11_22h2 - No
Operating System microsoft windows_11_23h2 - No
Operating System microsoft windows_11_23h2 - No
Operating System microsoft windows_server_2019 - No
Operating System microsoft windows_server_2022 - No
Operating System microsoft windows_server_2022_23h2 - No
Application microsoft .net_framework < 4.8.04690.02 Yes
Application microsoft .net_framework 3.5 Yes
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_10_21h2 - No
Operating System microsoft windows_10_21h2 - No
Operating System microsoft windows_10_21h2 - No
Operating System microsoft windows_10_22h2 - No
Operating System microsoft windows_10_22h2 - No
Operating System microsoft windows_10_22h2 - No
Operating System microsoft windows_11_21h2 - No
Operating System microsoft windows_11_21h2 - No
Operating System microsoft windows_11_22h2 - No
Operating System microsoft windows_11_22h2 - No
Operating System microsoft windows_server_2019 - No
Operating System microsoft windows_server_2022 - No
Operating System microsoft windows_server_2022_23h2 - No
Application microsoft .net_framework 3.5 Yes
Application microsoft .net_framework 4.7.2 Yes
Operating System microsoft windows_10_1607 - No
Operating System microsoft windows_10_1607 - No
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_10_1809 - No
Operating System microsoft windows_server_2016 - No
Operating System microsoft windows_server_2019 - No
Application microsoft .net_framework 2.0 Yes
Operating System microsoft windows_server_2008 - No
Application microsoft .net < 6.0.26 Yes
Application microsoft .net < 7.0.15 Yes
Application microsoft .net 8.0.0 Yes

References