Re: Microsoft Security Advisory CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider Information Disclosure Vulnerability

Sachidhanantham Ramalingam 16 Reputation points
2024-02-23T08:30:15.4+00:00

Hi, We are using some VB.NET Windows/Web Applications, C#.Net Windows Class Library/Windows Service Applications, Framework 4.5/4.8 have been used in all of them and referred System.Data.SqlClient for SQL Server activities. Clients are using Framework 4.8 where our application is running. Recently, we came to know about "Microsoft Security Advisory CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data provider Information Disclosure Vulnerability" , so could you please provide your thoughts that do we need to take any steps to overcome this Vulnerability? Note: We are also using VB 6.0 Application which refers ADODB for SQL Server activities - Is any change required in that area?

Thanks,
--Sachi...

Developer technologies | .NET | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jiachen Li-MSFT 34,221 Reputation points Microsoft External Staff
    2024-02-26T09:04:38.1666667+00:00

    Hi @Sachidhanantham Ramalingam ,

    You have to update both packages to their respective secure versions, please see the links below for details. https://github.com/dotnet/announcements/issues/292

    Best Regards.

    Jiachen Li


    If the answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.