Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-7270
HistoryDec 20, 2016 - 6:59 a.m.

Information disclosure

2016-12-2006:59:00
PRIOn knowledge base
www.prio-n.com
4

7.2 High

AI Score

Confidence

Low

0.039 Low

EPSS

Percentile

92.0%

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka “.NET Information Disclosure Vulnerability.”

CPENameOperatorVersion
.net_frameworkeq4.6.2

7.2 High

AI Score

Confidence

Low

0.039 Low

EPSS

Percentile

92.0%