CVE

Id
94090  
CVE No.
CVE-2016-7270  
Status
Candidate  
Description
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."  
Phase
Assigned (20160909)  
Votes
None (candidate not yet proposed)  
Comments