CVE-2016-7270

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
20/12/2016
Last modified:
12/04/2025

Description

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*