cbcvebase.
CVE-2016-7270
published 2016-12-20

CVE-2016-7270: The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always…

PriorityP352high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
20.01%
97.1th percentile
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
msrcmicrosoft_net_framework_4.6.2_on_windows_10_version_1607_for_32-bit_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_10_version_1607_for_x64-based_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_7_for_32-bit_systems_service_pack_1
msrcmicrosoft_net_framework_4.6.2_on_windows_7_for_x64-based_systems_service_pack_1
msrcmicrosoft_net_framework_4.6.2_on_windows_8.1_for_32-bit_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_8.1_for_x64-based_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2008_r2_for_x64-based_systems_s
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2012
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2012_r2
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2016

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.