The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka .NET Information Disclosure Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
.net_framework | Microsoft | 4.6.2 (including) | 4.6.2 (including) |