CVE-2016-7270
published 2016-12-20CVE-2016-7270: The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always…
PriorityP352high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
20.01%
97.1th percentile
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_8.1_for_32-bit_systems | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_8.1_for_x64-based_systems | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_server_2008_r2_for_x64-based_systems_s | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_server_2012 | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_server_2012_r2 | — | — |
| msrc | microsoft_net_framework_4.6.2_on_windows_server_2016 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET Framework Information Disclosure Vulnerability
vendor_msrc·2016-12-13·CVSS 7.5
CVE-2016-7270 [HIGH] .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Microsoft .NET 4.6.2 Framework’s Data Provider for SQL Server that could allow an attacker to access information that should be defended by the Always Encrypted feature. The vulnerability is caused when .NET Framework improperly uses a developer-supplied key. When this key is misused, it is also possible for access to data to be temporarily lost.
To exploit the vulnerability, an attacker who can access the incorrectly encrypted data could attempt to decrypt the data using an easily guessable key.
The security update addresses the vulnerability by correcting the way .NET Framework handles the developer-supplied key, and thus properly defends the data.
.NET Framework: .NET Fra
GHSA
GHSA-8gpg-cpw5-pw9g: The Data Provider for SQL Server in Microsoft
ghsa_unreviewed·2022-05-14
CVE-2016-7270 [HIGH] GHSA-8gpg-cpw5-pw9g: The Data Provider for SQL Server in Microsoft
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - December 2016
blogs_talos·2016-12-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - December 2016
The final patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 12 bulletins addressing 48 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Microsoft Graphics Components, Microsoft Uniscribe, and Adobe Flash Player. The remaining seven bulletins are rated important and address vulnerabilities in various Windows components including kernel, crypto driver, and installer.
### Bulletins Rated Critical Microsoft bulletins MS16-144 through MS16-148 and MS16-154 are rated as critical in this month's release.
MS16-144 is the Internet Explorer bulletin for this month. It addresses a total of ni
Talos
Microsoft Patch Tuesday - December 2016
blogs_talos·2016-12-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - December 2016
## Microsoft Patch Tuesday - December 2016
The final patch Tuesday of 2016 has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month's release contains 12 bulletins addressing 48 vulnerabilities. Six bulletins are rated critical and address vulnerabilities in Internet Explorer, Edge, Microsoft Graphics Components, Microsoft Uniscribe, and Adobe Flash Player. The remaining seven bulletins are rated important and address vulnerabilities in various Windows components including kernel, crypto driver, and installer.
## Bulletins Rated Critical Microsoft bulletins MS16-144 through MS16-148 and MS16-154 are rated as critical in this month's release.
MS16-144 is the Internet Explorer bulletin
http://www.securityfocus.com/bid/94741http://www.securitytracker.com/id/1037455https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-155http://www.securityfocus.com/bid/94741http://www.securitytracker.com/id/1037455https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-155
2016-12-20
Published