Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-7270

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.37
EPSS Ranking 97.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2016-7270


Contact Us

Shodan ® - All rights reserved