PT-2016-7281 · Microsoft · .Net Framework

Publicado

2016-12-13

·

Atualizado

2018-10-12

·

CVE-2016-7270

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework version 4.6.2
Description An information disclosure issue exists due to the improper handling of a developer-supplied key by the Data Provider for SQL Server in Microsoft .NET Framework. This allows remote attackers to bypass the Always Encrypted protection mechanism, potentially obtaining sensitive cleartext information. The vulnerability is caused by key guessability.
Recommendations For Microsoft .NET Framework version 4.6.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7270

Produtos afetados

.Net Framework