CVE-2016-7270
20.12.2016, 06:59
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."Enginsight
Vendor | Product | Version |
---|---|---|
microsoft | .net_framework | 4.6.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References