CVE Published: 20/12/2016 |
CVE Updated: 06/08/2024 |
CVE Year: 2016 Source: microsoft |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2016-7270 Description
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."