CVE-2016-7270: Microsoft .NET Framework

High severity, CVSS 7.5. EPSS: 20% chance of exploitation in the next 30 days.

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."

Affected products

Published 2016-12-20. Last modified 2026-06-17.