CVE-2016-7270: Microsoft .NET Framework
High severity, CVSS 7.5. EPSS: 20% chance of exploitation in the next 30 days.
The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability."
Affected products
- Microsoft .NET Framework: version 4.6.2 only
Published 2016-12-20. Last modified 2026-06-17.