Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.