Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-41064

Опубликовано: 08 нояб. 2022
Источник: msrc
CVSS3: 5.8
EPSS Низкий

Описание

.NET Framework Information Disclosure Vulnerability

FAQ

If I am using System.Data.SqlClient or Microsoft.Data.SqlClient, what do I need to do to be protected from this vulnerability?

Customers using either the System.Data.SqlClient or Microsoft.Data.SqlClient NuGet Packages need to do the following to be protected:

  • If you are using System.Data.SqlClient on .NET Framework you must install the November update for .NET Framework
  • If you are using System.Data.SqlClient on .NET Core, .NET 5 or .NET 6 you must update the nuget package to an updated version as listed in the affected packages.
  • If you are using Microsoft.Data.SqlClient, anywhere (.NET Core, .NET 5/6, .NET Framework) and you are using a version that is vulnerable you must update as listed in the affected packages.

Please see Microsoft Security Advisory CVE 2022-41064 | .NET Information Disclosure Vulnerability for more information.

According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?

Exploiting this vulnerability requires an attacker to be within the SQL Connection Pool.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to exhaust all the threads in the thread pool.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

In this case, a successful attack could cause the attacker access queries from other users in the SQL Connection Pool.

Обновления

ПродуктСтатьяОбновление
Nuget 4.8.5
Nuget 2.1.2
Microsoft .NET Framework 4.8 on Windows 10 Version 21H2 for ARM64-based Systems
Microsoft .NET Framework 4.8 on Windows 10 Version 21H2 for 32-bit Systems
Microsoft .NET Framework 4.8 on Windows 10 Version 21H2 for x64-based Systems
Microsoft .NET Framework 4.8 on Windows Server 2012 R2
Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems
Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems
Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)
Microsoft .NET Framework 4.8 on Windows RT 8.1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 34%
0.00137
Низкий

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
ubuntu
около 3 лет назад

.NET Framework Information Disclosure Vulnerability

CVSS3: 5.8
nvd
около 3 лет назад

.NET Framework Information Disclosure Vulnerability

CVSS3: 5.8
github
около 3 лет назад

.NET Information Disclosure Vulnerability

CVSS3: 5.8
fstec
около 3 лет назад

Уязвимость программной платформы Microsoft.NET Framework, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 34%
0.00137
Низкий

5.8 Medium

CVSS3