CVE-2024-0056
published 2024-01-09CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
PriorityP352high8.7CVSS 3.1
AVNACHPRNUINSCCHIHAN
EPSS
1.17%
63.9th percentile
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.data.sqlclient | >= 0 < 2.1.7 | 2.1.7 |
| microsoft | microsoft.data.sqlclient | >= 2.0 < 2.1.7 | 2.1.7 |
| microsoft | microsoft.data.sqlclient | >= 2.1 < 2.1.7 | 2.1.7 |
| microsoft | microsoft.data.sqlclient | >= 3.0 < 3.1.5 | 3.1.5 |
| microsoft | microsoft.data.sqlclient | >= 3.0.0 < 3.1.5 | 3.1.5 |
| microsoft | microsoft.data.sqlclient | >= 3.1 < 3.1.5 | 3.1.5 |
| microsoft | microsoft.data.sqlclient | >= 4.0 < 4.0.5 | 4.0.5 |
| microsoft | microsoft.data.sqlclient | >= 4.0.0 < 4.0.5 | 4.0.5 |
| microsoft | microsoft.data.sqlclient | >= 5.0 < 5.1.3 | 5.1.3 |
| microsoft | microsoft.data.sqlclient | >= 5.0.0 < 5.1.3 | 5.1.3 |
| microsoft | microsoft.data.sqlclient | >= 5.1 < 5.1.3 | 5.1.3 |
| microsoft | microsoft_net_framework_2.0_service_pack_2 | >= 2.0.0 < 3.0.50727.8976 | 3.0.50727.8976 |
| microsoft | microsoft_net_framework_3.5_and_4.7.2 | >= 4.7.0 < 4.7.04081.03 | 4.7.04081.03 |
| microsoft | microsoft_net_framework_3.5_and_4.8 | >= 4.8.0 < 4.8.04690.02 | 4.8.04690.02 |
| microsoft | microsoft_net_framework_3.5_and_4.8.1 | >= 4.8.1 < 4.8.09214.01 | 4.8.09214.01 |
| microsoft | microsoft_net_framework_4.6.2_4.7_4.7.1_4.7.2 | >= 4.7.0 < 4.7.04081.02 | 4.7.04081.02 |
| microsoft | microsoft_net_framework_4.8 | >= 4.8.0 < 4.8.04690.02 | 4.8.04690.02 |
| microsoft | microsoft_sql_server_2022 | < 16.0.4100.1 | 16.0.4100.1 |
| microsoft | microsoft_sql_server_2022 | >= 16.0.0 < 16.0.1110.1 | 16.0.1110.1 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.23 | 17.2.23 |
| microsoft | microsoft_visual_studio_2022_version_17.4 | >= 17.4.0 < 17.4.15 | 17.4.15 |
| microsoft | microsoft_visual_studio_2022_version_17.6 | >= 17.6.0 < 17.6.11 | 17.6.11 |
| microsoft | microsoft_visual_studio_2022_version_17.8 | >= 17.8.0 < 17.8.4 | 17.8.4 |
| microsoft | net | — | — |
| microsoft | net | >= 6.0.0 < 6.0.26 | 6.0.26 |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
vendor_msrc8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS
cisa_ics·2025-11-13·CVSS 9.3
[CRITICAL] Siemens COMOS
ICS Advisory
##
Siemens COMOS
Release DateNovember 13, 2025
Alert CodeICSA-25-317-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Incomplete List of Disallowed Inputs, Cleartext Transmission of Sensitive Information
## 2. RISK EVALUATION
Successf
CISA ICS
Siemens INTRALOG WMS
cisa_ics·2025-05-15·CVSS 8.7
[HIGH] Siemens INTRALOG WMS
ICS Advisory
##
Siemens INTRALOG WMS
Release DateMay 15, 2025
Alert CodeICSA-25-135-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: INTRALOG WMS
- Vulnerabilities: Cleartext Transmission of Sensitive Information, Uncontrolled Resource Consumption, Use After Free, Improper
CISA ICS
Siemens SIDIS Prime
cisa_ics·2025-04-10
Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateApril 10, 2025
Alert CodeICSA-25-100-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIDIS Prime
- Vulnerabilities: Race Condition Enabling Link Following, Improper Validation of Integrity Check Value, Unchecked Input for Loo
CISA ICS
Siemens INTRALOG WMS
cisa_ics·2024-08-15·CVSS 8.7
[HIGH] Siemens INTRALOG WMS
ICS Advisory
##
Siemens INTRALOG WMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable from adjacent network/low attack complexity
- Vendor: Siemens
- Equipment: INTRALOG WMS
- Vulnerabilities: Cleartext Transmission of Sensitive Information, Heap-based Buffer Overflow
## 2. RISK EVALU
CISA ICS
Siemens Teamcenter Visualization and JT2Go
cisa_ics·2024-08-15·CVSS 7.3
[HIGH] Siemens Teamcenter Visualization and JT2Go
ICS Advisory
##
Siemens Teamcenter Visualization and JT2Go
Release DateAugust 15, 2024
Alert CodeICSA-24-228-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 7.3
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: Teamcenter Visualization and JT2Go
- Vulnerabilities: Out-of-bounds Read, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exp
Microsoft
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
vendor_msrc·2024-01-09·CVSS 8.7
CVE-2024-0056 [HIGH] CWE-319 Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This is called a machine-in-the-middle (MITM) attack.
FAQ: If I am using System.Data.SqlClient or Microsoft.Data.SqlClient, what do I need to do to be protected from this vulnerability?
Customers developing applications using either the System.Data.SqlClient or Microsoft.Data.SqlClient NuGet Packages need to do the following to be protected:
If you are using System.Data.SqlClient on .NET Framework you
Red Hat
dotnet: Information Disclosure: MD.SqlClient(MDS) & System.data.SQLClient (SDS)
vendor_redhat·2024-01-09·CVSS 8.7
CVE-2024-0056 [HIGH] CWE-420 dotnet: Information Disclosure: MD.SqlClient(MDS) & System.data.SQLClient (SDS)
dotnet: Information Disclosure: MD.SqlClient(MDS) & System.data.SQLClient (SDS)
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
A vulnerability was found in the .NET Framework. This vulnerability exists in the Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider where an attackercan perform an AiTM (adversary-in-the-middle) attack between the SQL client and the SQL server. This may allow the attacker to steal authentication credentials intended for the database server, even if the connection is established over an encrypted channel like TLS.
Statement: This flaw allows attackers to execute an adversary-in-the-middle (AiTM) attack, potentially enabling the theft of authentication credentials even when the connecti
GHSA
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
ghsa·2024-01-09
CVE-2024-0056 [HIGH] CWE-319 Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
OSV
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
osv·2024-01-09
CVE-2024-0056 [HIGH] Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
No detection rules found.
No public exploits indexed.
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 8.8
[HIGH] The January 2024 Security Update Review
# The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs
2024/01/09
Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Adobe Patches for January 2024
For January, Adobe released a single patch addressing six CVEs in Substance 3D Stager. All six bugs are rated Important with the most severe allowing arbitrary code execution.
None of the bugs fixed by Adobe this month are listed as publicly known or under active attack at the time of release. Adobe categorizes t
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs Jan 09, 2024 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs 2024/01/09 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
8
Bleepingcomputer
Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
blogs_bleepingcomputer·2024-01-09·CVSS 8.8
[HIGH] Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
## Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
7 Security Feature Bypass Vulnerabilities
12 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 49 flaws does not include 4 Microsoft Edge flaws fixed on January 5th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034123 cumulative update and Windows 10 KB5034122 update .
## This month's interesting flaws
While there were no actively exploited or publicly disclosed vulnerabilities this month, some flaws are more interesting than others.
Microsoft fixes an Office Remo
Trendmicro
The January 2024 Security Update Review
blogs_trendmicro·2024-01-09·CVSS 9.1
[CRITICAL] The January 2024 Security Update Review
## The January 2024 Security Update Review
Get the January 2024 security update and review.
By: Dustin Childs Jan 09, 2024 Read time: ( words)
Save to Folio
Welcome to the first patch Tuesday of 2024. As expected, Microsoft and Adobe have released their latest security patches. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-20700
Windows Hyper-V Remote Code Execution Vulnerability
Critical
7.5
No
No
RCE
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Critical
9
No
No
SFB
CVE-2024-0057
.NET and Visual Studio Framework Security Feature Bypass Vulnerability
Important
2024-01-09
Published