CVE-2022-41064
published 2022-11-09CVE-2022-41064: .NET Framework Information Disclosure Vulnerability
PriorityP423medium5.8CVSS 3.1
AVAACHPRLUINSCCHINAN
EPSS
0.75%
50.7th percentile
.NET Framework Information Disclosure Vulnerability
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | >= 3.0.0.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | microsoft_net_framework_4.6.2 | >= 4.7.0 < 4.7.04005.02 | 4.7.04005.02 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.04005.02 | 4.7.04005.02 |
| microsoft | microsoft_net_framework_4.6_4.6.2 | >= 10.0.0.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | microsoft_net_framework_4.7.2 | >= 10.0.0.0 < 10.0.04005.02 | 10.0.04005.02 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.04584.08 | 4.8.04584.08 |
| microsoft | microsoft_net_framework_4.8.1 | >= 4.8.0.0 < 4.8.09110.07 | 4.8.09110.07 |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | nuget | < 1.1.4 | 1.1.4 |
| microsoft | nuget | >= 2.0.0 < 2.1.2 | 2.1.2 |
| microsoft | nuget | >= 3.0.0 < 4.8.5 | 4.8.5 |
| microsoft | nuget_2.1.2 | >= 1.0.0 < 2.1.2 | 2.1.2 |
| microsoft | nuget_4.8.5 | >= 1.0.0 < 4.8.4 | 4.8.4 |
| msrc | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2 | — | — |
| msrc | microsoft_net_framework_4.6.2 | — | — |
| msrc | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | — | — |
| msrc | microsoft_net_framework_4.6_4.6.2 | — | — |
| msrc | microsoft_net_framework_4.7.2 | — | — |
| msrc | microsoft_net_framework_4.8 | — | — |
| msrc | microsoft_net_framework_4.8.1 | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
vendor_msrc5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET Framework Information Disclosure Vulnerability
vendor_msrc·2022-11-08·CVSS 5.8
CVE-2022-41064 [MEDIUM] .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
FAQ: If I am using System.Data.SqlClient or Microsoft.Data.SqlClient, what do I need to do to be protected from this vulnerability?
Customers using either the System.Data.SqlClient or Microsoft.Data.SqlClient NuGet Packages need to do the following to be protected:
If you are using System.Data.SqlClient on .NET Framework you must install the November update for .NET Framework
If you are using System.Data.SqlClient on .NET Core, .NET 5 or .NET 6 you must update the nuget package to an updated version as listed in the affected packages.
If you are using Microsoft.Data.SqlClient, anywhere (.NET Core, .NET 5/6, .NET Framework) and you are using a version that is vulnerable you must update as listed in the affected packages.
Please see Micr
GHSA
.NET Information Disclosure Vulnerability
ghsa·2022-11-08
CVE-2022-41064 [MEDIUM] .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET, .NET Core and .NET Framework's System.Data.SqlClient and Microsoft.Data.SqlClient NuGet Packages.
A vulnerability exists in System.Data.SqlClient and Microsoft.Data.SqlClient libraries where a timeout occurring under high load can cause incorrect data to be returned as the result of an asynchronously executed query.
## Mitigation factors
If you are not talking to Microsoft SQL Server from your application you are not affected by this vulnerability.
### How do I know if I am affected?
.NET has two types of dependencies: direct and transitive. Direct dependencies are dependencies where you specifically add a package to your project, transitive de
OSV
.NET Information Disclosure Vulnerability
osv·2022-11-08
CVE-2022-41064 [MEDIUM] .NET Information Disclosure Vulnerability
.NET Information Disclosure Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET, .NET Core and .NET Framework's System.Data.SqlClient and Microsoft.Data.SqlClient NuGet Packages.
A vulnerability exists in System.Data.SqlClient and Microsoft.Data.SqlClient libraries where a timeout occurring under high load can cause incorrect data to be returned as the result of an asynchronously executed query.
## Mitigation factors
If you are not talking to Microsoft SQL Server from your application you are not affected by this vulnerability.
### How do I know if I am affected?
.NET has two types of dependencies: direct and transitive. Direct dependencies are dependencies where you specifically add a package to your project, transitive de
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-09
Published