Lucene search

K
cvelistMicrosoftCVELIST:CVE-2016-7270
HistoryDec 20, 2016 - 5:54 a.m.

CVE-2016-7270

2016-12-2005:54:00
microsoft
www.cve.org
1

7.4 High

AI Score

Confidence

High

0.039 Low

EPSS

Percentile

92.0%

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka “.NET Information Disclosure Vulnerability.”

7.4 High

AI Score

Confidence

High

0.039 Low

EPSS

Percentile

92.0%