cbcvebase.
CVE-2016-7270
published 2016-12-20

CVE-2016-7270: The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always…

high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
msrcmicrosoft_net_framework_4.6.2_on_windows_10_version_1607_for_32-bit_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_10_version_1607_for_x64-based_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_7_for_32-bit_systems_service_pack_1
msrcmicrosoft_net_framework_4.6.2_on_windows_7_for_x64-based_systems_service_pack_1
msrcmicrosoft_net_framework_4.6.2_on_windows_8.1_for_32-bit_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_8.1_for_x64-based_systems
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2008_r2_for_x64-based_systems_s
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2012
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2012_r2
msrcmicrosoft_net_framework_4.6.2_on_windows_server_2016