CVE-2008-5100
Microsoft .NET Framework 2.0.50727 - Strong Name Verification Bypass via Public Key Token
Title source: llmDescription
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498311/100/0/threaded
Various Sources x_refsource_misc
http://www.applicationsecurity.co.il/.NET-Framework-Rootkits.aspx
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/4605
Exploit x_refsource_misc
http://www.applicationsecurity.co.il/LinkClick.aspx?fileticket=ycIS1bewMBI%3d&tabid=161&mid=555
Scores
EPSS
0.0837
EPSS Percentile
94.4%
Details
CWE
CWE-310
Status
published
Products (1)
microsoft/.net_framework
2.0.50727
Published
Nov 17, 2008
Tracked Since
Feb 18, 2026