CVE-2016-7270

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*

Information

Published : 2016-12-19 22:59

Updated : 2018-10-12 15:14


NVD link : CVE-2016-7270

Mitre link : CVE-2016-7270


JSON object : View

CWE
CWE-310

Cryptographic Issues

Advertisement

dedicated server usa

Products Affected

microsoft

  • .net_framework