CVE-2008-5100

Microsoft .NET Framework 2.0.50727 - Strong Name Verification Bypass via Public Key Token

Title source: llm
STIX 2.1

Description

The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498311/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4605

Scores

EPSS 0.0837
EPSS Percentile 94.4%

Details

CWE
CWE-310
Status published
Products (1)
microsoft/.net_framework 2.0.50727
Published Nov 17, 2008
Tracked Since Feb 18, 2026