First published: Wed Dec 20 2023(Updated: )
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET 8.0 | ||
Microsoft .NET 6.0 | ||
Microsoft .NET 7.0 | ||
nuget/Microsoft.Data.SqlClient | >=5.0.0<5.1.3 | 5.1.3 |
nuget/Microsoft.Data.SqlClient | >=4.0.0<4.0.5 | 4.0.5 |
nuget/Microsoft.Data.SqlClient | >=3.0.0<3.1.5 | 3.1.5 |
nuget/System.Data.SqlClient | <4.8.6 | 4.8.6 |
nuget/Microsoft.Data.SqlClient | <2.1.7 | 2.1.7 |
redhat/.NET SDK 6.0.126 and .NET Runtime 6.0.26 and .NET SDK 7.0.115 and .NET Runtime | <7.0.15 | 7.0.15 |
Microsoft .NET Framework | =4.6.2=4.7=4.7.1=4.7.2 | |
Microsoft .NET Framework | =2.0 | |
Microsoft .NET Framework | =4.8 | |
Microsoft .NET Framework | =4.6.2=4.7=4.7.1=4.7.2 | |
Microsoft .NET Framework | =4.6.2=4.7=4.7.1=4.7.2 | |
Microsoft .NET Framework | =4.8 | |
Microsoft .NET Framework | =4.8 | |
Microsoft .NET Framework | =4.8 | |
Microsoft .NET Framework | =3.5=4.7.2 | |
Microsoft .NET Framework | =3.5=4.8 | |
Microsoft .NET Framework | =3.5=4.7.2 | |
Microsoft .NET Framework | =3.5=4.8.1 | |
Microsoft .NET Framework | =3.5=4.8.1 | |
Microsoft .NET Framework | =3.5=4.8 | |
Microsoft .NET Framework | =3.5=4.8.1 | |
Microsoft .NET Framework | =3.5=4.8 | |
Microsoft .NET Framework | =3.5=4.8 | |
Microsoft .NET Framework | =3.5=4.8.1 | |
Microsoft .NET Framework | =3.5=4.8.1 | |
Microsoft SQL Server 2022 | ||
Microsoft SQL Server 2022 | ||
Microsoft SQL Server | ||
Microsoft.Data.SqlClient | ||
Microsoft.Data.SqlClient | ||
Microsoft.Data.SqlClient | ||
Microsoft.Data.SqlClient | ||
Microsoft.Data.SqlClient | ||
Visual Studio Professional 2022 | =17.4 | |
Visual Studio Professional 2022 | =17.2 | |
Visual Studio Professional 2022 | =17.8 | |
Microsoft.Data.SqlClient | >=2.1<2.1.7 | |
Microsoft.Data.SqlClient | >=3.1<3.1.5 | |
Microsoft.Data.SqlClient | >=4.0<4.0.5 | |
Microsoft.Data.SqlClient | >=5.1<5.1.3 | |
Microsoft SQL Server | =2022 | |
Microsoft SQL Server | =2022-cumulative_update_10 | |
Microsoft.Data.SqlClient | <4.8.6 | |
Visual Studio Professional 2022 | >=17.2<17.2.23 | |
Visual Studio Professional 2022 | >=17.4<17.4.15 | |
Visual Studio Professional 2022 | >=17.6<17.6.11 | |
Visual Studio Professional 2022 | >=17.8<17.8.4 | |
All of | ||
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft .NET Framework | >=4.8<4.8.04690.02 | |
All of | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft .NET Framework | >=4.8<4.8.04690.01 | |
All of | ||
Any of | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Any of | ||
Microsoft .NET Framework | =4.6.2 | |
Microsoft .NET Framework | =4.7 | |
Microsoft .NET Framework | =4.7.1 | |
Microsoft .NET Framework | =4.7.2 | |
All of | ||
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 22H2 | ||
Microsoft Windows 10 22H2 | ||
Microsoft Windows 10 22H2 | ||
Windows 11 | ||
Windows 11 | ||
Windows 11 | ||
Windows 11 | ||
Windows 11 | ||
Windows 11 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Any of | ||
Microsoft .NET Framework | =3.5 | |
Microsoft .NET Framework | =4.8.1 | |
All of | ||
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 22H2 | ||
Microsoft Windows 10 22H2 | ||
Microsoft Windows 10 22H2 | ||
Windows 11 | ||
Windows 11 | ||
Windows 11 | ||
Windows 11 | ||
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows Server 2022 | ||
Any of | ||
Microsoft .NET Framework | >=4.8<4.8.04690.02 | |
Microsoft .NET Framework | =3.5 | |
All of | ||
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 | ||
Any of | ||
Microsoft .NET Framework | =3.5 | |
Microsoft .NET Framework | =4.7.2 | |
All of | ||
Microsoft Windows Server | =sp2 | |
Microsoft .NET Framework | =2.0-sp2 | |
Microsoft .NET Framework | >=6.0.0<6.0.26 | |
Microsoft .NET Framework | >=7.0.0<7.0.15 | |
Microsoft .NET Framework | =8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0056 is rated as a critical severity vulnerability.
You can fix CVE-2024-0056 by applying the latest security patches provided by Microsoft for the affected products.
CVE-2024-0056 affects Microsoft.Data.SqlClient, System.Data.SqlClient, and various versions of the .NET Framework along with SQL Server 2022.
Yes, CVE-2024-0056 is exploitable remotely, allowing attackers to bypass security features.
Exploiting CVE-2024-0056 could lead to unauthorized access and manipulation of sensitive data.