The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka .NET Information Disclosure Vulnerability.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| .net_framework | Microsoft | 4.6.2 (including) | 4.6.2 (including) |