Security features bypass in Microsoft products - CVE-2024-0056

 

Security features bypass in Microsoft products - CVE-2024-0056

Published: January 10, 2024


Vulnerability identifier: #VU85244
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0056
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to security features bypass in Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider. A remote attacker can evade the encryption used in a TLS connection.


Affected software

System.Data.SqlClient
Microsoft.Data.SqlClient
.NET
INTRALOG WMS
Robotic Process Automation for Cloud Pak
Live Optics Windows Collector
Microsoft .NET Framework
Microsoft SQL Server
Visual Studio
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Anolis OS
dotnet-targeting-pack-6.0
dotnet-runtime-6.0
dotnet-hostfxr-6.0
aspnetcore-runtime-6.0
aspnetcore-targeting-pack-6.0
dotnet-host
dotnet-apphost-pack-6.0
dotnet6.0
rh-dotnet60-dotnet (Red Hat package)
dotnet6.0 (Red Hat package)
netstandard-targeting-pack-2.1
dotnet-templates-6.0
dotnet-sdk-6.0-source-built-artifacts
dotnet-sdk-6.0
dotnet
dotnet7.0 (Red Hat package)
dotnet8.0 (Red Hat package)

How to mitigate CVE-2024-0056

Install updates from vendor's website.

INTRALOG WMS - update to 4
dotnet-targeting-pack-6.0 - update to 6.0.26-1.0.1
dotnet-runtime-6.0 - update to 6.0.26-1.0.1
dotnet-hostfxr-6.0 - update to 6.0.26-1.0.1
aspnetcore-runtime-6.0 - update to 6.0.26-1.0.1
aspnetcore-targeting-pack-6.0 - update to 6.0.26-1.0.1
dotnet-host - update to 6.0.26-1.0.1
dotnet-apphost-pack-6.0 - update to 6.0.26-1.0.1
dotnet6.0 - update to 6.0.126-1
rh-dotnet60-dotnet (Red Hat package) - update to 6.0.126-1.el7_9
dotnet6.0 (Red Hat package) - addressed in versions 6.0.126-1.el8_9, 6.0.126-1.el9_3
netstandard-targeting-pack-2.1 - update to 6.0.126-1.0.1
dotnet-templates-6.0 - update to 6.0.126-1.0.1
dotnet-sdk-6.0-source-built-artifacts - update to 6.0.126-1.0.1
dotnet-sdk-6.0 - update to 6.0.126-1.0.1
dotnet - update to 6.0.126-1.0.1
dotnet7.0 (Red Hat package) - addressed in versions 7.0.115-1.el8_9, 7.0.115-1.el9_3
dotnet8.0 (Red Hat package) - addressed in versions 8.0.101-1.el8_9, 8.0.101-1.el9_3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.14, 23.0.15
Live Optics Windows Collector - update to 25.1.13.152

External References

Related Security Bulletins