CVE-2016-7270
EUVD-2016-812620.12.2016, 06:59
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | .net_framework | 4.6.2 |
𝑥
= Vulnerable software versions
Windows Releases
Platform | Version | ||||
|---|---|---|---|---|---|
| Windows 10 |
| ||||
| Windows 7 |
| ||||
| Windows 8.1 |
| ||||
| Windows Server 2008 R2 |
| ||||
| Windows Server 2012 |
| ||||
| Windows Server 2012 R2 |
| ||||
| Windows Server 2016 |
|
Common Weakness Enumeration
References