cbcvebase.
CVE-2024-0056
published 2024-01-09

CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

PriorityP352high8.7CVSS 3.1
AVNACHPRNUINSCCHIHAN
EPSS
1.17%
63.9th percentile
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft.data.sqlclient>= 0 < 2.1.72.1.7
microsoftmicrosoft.data.sqlclient>= 2.0 < 2.1.72.1.7
microsoftmicrosoft.data.sqlclient>= 2.1 < 2.1.72.1.7
microsoftmicrosoft.data.sqlclient>= 3.0 < 3.1.53.1.5
microsoftmicrosoft.data.sqlclient>= 3.0.0 < 3.1.53.1.5
microsoftmicrosoft.data.sqlclient>= 3.1 < 3.1.53.1.5
microsoftmicrosoft.data.sqlclient>= 4.0 < 4.0.54.0.5
microsoftmicrosoft.data.sqlclient>= 4.0.0 < 4.0.54.0.5
microsoftmicrosoft.data.sqlclient>= 5.0 < 5.1.35.1.3
microsoftmicrosoft.data.sqlclient>= 5.0.0 < 5.1.35.1.3
microsoftmicrosoft.data.sqlclient>= 5.1 < 5.1.35.1.3
microsoftmicrosoft_net_framework_2.0_service_pack_2>= 2.0.0 < 3.0.50727.89763.0.50727.8976
microsoftmicrosoft_net_framework_3.5_and_4.7.2>= 4.7.0 < 4.7.04081.034.7.04081.03
microsoftmicrosoft_net_framework_3.5_and_4.8>= 4.8.0 < 4.8.04690.024.8.04690.02
microsoftmicrosoft_net_framework_3.5_and_4.8.1>= 4.8.1 < 4.8.09214.014.8.09214.01
microsoftmicrosoft_net_framework_4.6.2_4.7_4.7.1_4.7.2>= 4.7.0 < 4.7.04081.024.7.04081.02
microsoftmicrosoft_net_framework_4.8>= 4.8.0 < 4.8.04690.024.8.04690.02
microsoftmicrosoft_sql_server_2022< 16.0.4100.116.0.4100.1
microsoftmicrosoft_sql_server_2022>= 16.0.0 < 16.0.1110.116.0.1110.1
microsoftmicrosoft_visual_studio_2022_version_17.2>= 17.2.0 < 17.2.2317.2.23
microsoftmicrosoft_visual_studio_2022_version_17.4>= 17.4.0 < 17.4.1517.4.15
microsoftmicrosoft_visual_studio_2022_version_17.6>= 17.6.0 < 17.6.1117.6.11
microsoftmicrosoft_visual_studio_2022_version_17.8>= 17.8.0 < 17.8.417.8.4
microsoftnet
microsoftnet>= 6.0.0 < 6.0.266.0.26

CVSS provenance

nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
vendor_msrc8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.