ZeroHour

CVE-2016-7270

CVSS 3.0
7.5 high
EPSS
20%p97
Published
()
Modified
Description

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."

Vendors
microsoft
Products
.net framework
Weakness
CWE-310
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news