The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
References
Configurations
History
21 Nov 2024, 02:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/94741 - | |
References | () http://www.securitytracker.com/id/1037455 - | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-155 - |
Information
Published : 2016-12-20 06:59
Updated : 2024-11-21 02:57
NVD link : CVE-2016-7270
Mitre link : CVE-2016-7270
CVE.ORG link : CVE-2016-7270
JSON object : View
Products Affected
microsoft
- .net_framework
CWE
CWE-310
Cryptographic Issues