60
CVE-2016-7270
—CVSS 3.0
7.5 high
EPSS
20%p97
Published
()
Modified
Description
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
- Vendors
- microsoft
- Products
- .net framework
- Weakness
- CWE-310
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N