8.7

CVE-2024-0056

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability

Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftMicrosoft.Data.Sqlclient Version >= 2.1 < 2.1.7
MicrosoftMicrosoft.Data.Sqlclient Version >= 3.1 < 3.1.5
MicrosoftMicrosoft.Data.Sqlclient Version >= 4.0 < 4.0.5
MicrosoftMicrosoft.Data.Sqlclient Version >= 5.1 < 5.1.3
MicrosoftSql Server Version2022 HwPlatformx64
MicrosoftSql Server Version2022 Updatecumulative_update_10
MicrosoftSystem.Data.Sqlclient Version < 4.8.6
MicrosoftVisual Studio 2022 Version >= 17.2 < 17.2.23
MicrosoftVisual Studio 2022 Version >= 17.4 < 17.4.15
MicrosoftVisual Studio 2022 Version >= 17.6 < 17.6.11
MicrosoftVisual Studio 2022 Version >= 17.8 < 17.8.4
Microsoft.Net Framework Version >= 4.8 < 4.8.04690.02
   MicrosoftWindows 10 1607 Version- HwPlatformx64
   MicrosoftWindows 10 1607 Version- HwPlatformx86
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
   MicrosoftWindows Server 2016 Version-
Microsoft.Net Framework Version >= 4.8 < 4.8.04690.01
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
Microsoft.Net Framework Version4.6.2
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.7
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.7.1
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version4.7.2
   MicrosoftWindows Server 2008 Versionr2 Updatesp1 HwPlatformx64
   MicrosoftWindows Server 2012 Version-
   MicrosoftWindows Server 2012 Versionr2
Microsoft.Net Framework Version3.5
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows 10 21h2 Version- HwPlatformarm64
   MicrosoftWindows 10 21h2 Version- HwPlatformx64
   MicrosoftWindows 10 21h2 Version- HwPlatformx86
   MicrosoftWindows 10 22h2 Version- HwPlatformarm64
   MicrosoftWindows 10 22h2 Version- HwPlatformx64
   MicrosoftWindows 10 22h2 Version- HwPlatformx86
   MicrosoftWindows 11 21h2 Version- HwPlatformarm64
   MicrosoftWindows 11 21h2 Version- HwPlatformx64
   MicrosoftWindows 11 22h2 Version- HwPlatformarm64
   MicrosoftWindows 11 22h2 Version- HwPlatformx64
   MicrosoftWindows 11 23h2 Version- HwPlatformarm64
   MicrosoftWindows 11 23h2 Version- HwPlatformx64
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 2022 Version-
   MicrosoftWindows Server 2022 23h2 Version-
Microsoft.Net Framework Version4.8.1
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows 10 21h2 Version- HwPlatformarm64
   MicrosoftWindows 10 21h2 Version- HwPlatformx64
   MicrosoftWindows 10 21h2 Version- HwPlatformx86
   MicrosoftWindows 10 22h2 Version- HwPlatformarm64
   MicrosoftWindows 10 22h2 Version- HwPlatformx64
   MicrosoftWindows 10 22h2 Version- HwPlatformx86
   MicrosoftWindows 11 21h2 Version- HwPlatformarm64
   MicrosoftWindows 11 21h2 Version- HwPlatformx64
   MicrosoftWindows 11 22h2 Version- HwPlatformarm64
   MicrosoftWindows 11 22h2 Version- HwPlatformx64
   MicrosoftWindows 11 23h2 Version- HwPlatformarm64
   MicrosoftWindows 11 23h2 Version- HwPlatformx64
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 2022 Version-
   MicrosoftWindows Server 2022 23h2 Version-
Microsoft.Net Framework Version >= 4.8 < 4.8.04690.02
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows 10 21h2 Version- HwPlatformarm64
   MicrosoftWindows 10 21h2 Version- HwPlatformx64
   MicrosoftWindows 10 21h2 Version- HwPlatformx86
   MicrosoftWindows 10 22h2 Version- HwPlatformarm64
   MicrosoftWindows 10 22h2 Version- HwPlatformx64
   MicrosoftWindows 10 22h2 Version- HwPlatformx86
   MicrosoftWindows 11 21h2 Version- HwPlatformarm64
   MicrosoftWindows 11 21h2 Version- HwPlatformx64
   MicrosoftWindows 11 22h2 Version- HwPlatformarm64
   MicrosoftWindows 11 22h2 Version- HwPlatformx64
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 2022 Version-
   MicrosoftWindows Server 2022 23h2 Version-
Microsoft.Net Framework Version3.5
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows 10 21h2 Version- HwPlatformarm64
   MicrosoftWindows 10 21h2 Version- HwPlatformx64
   MicrosoftWindows 10 21h2 Version- HwPlatformx86
   MicrosoftWindows 10 22h2 Version- HwPlatformarm64
   MicrosoftWindows 10 22h2 Version- HwPlatformx64
   MicrosoftWindows 10 22h2 Version- HwPlatformx86
   MicrosoftWindows 11 21h2 Version- HwPlatformarm64
   MicrosoftWindows 11 21h2 Version- HwPlatformx64
   MicrosoftWindows 11 22h2 Version- HwPlatformarm64
   MicrosoftWindows 11 22h2 Version- HwPlatformx64
   MicrosoftWindows Server 2019 Version-
   MicrosoftWindows Server 2022 Version-
   MicrosoftWindows Server 2022 23h2 Version-
Microsoft.Net Framework Version3.5
   MicrosoftWindows 10 1607 Version- HwPlatformx64
   MicrosoftWindows 10 1607 Version- HwPlatformx86
   MicrosoftWindows 10 1809 Version- HwPlatformarm64
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows Server 2016 Version-
   MicrosoftWindows Server 2019 Version-
Microsoft.Net Framework Version4.7.2
   MicrosoftWindows 10 1607 Version- HwPlatformx64
   MicrosoftWindows 10 1607 Version- HwPlatformx86
   MicrosoftWindows 10 1809 Version- HwPlatformarm64
   MicrosoftWindows 10 1809 Version- HwPlatformx64
   MicrosoftWindows 10 1809 Version- HwPlatformx86
   MicrosoftWindows Server 2016 Version-
   MicrosoftWindows Server 2019 Version-
Microsoft.Net Framework Version2.0 Updatesp2
   MicrosoftWindows Server 2008 Version- Updatesp2 HwPlatformx64
Microsoft.Net Version >= 6.0.0 < 6.0.26
Microsoft.Net Version >= 7.0.0 < 7.0.15
Microsoft.Net Version8.0.0 Update-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.86% 0.75
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
secure@microsoft.com 8.7 2.2 5.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.