Vulnerability Name: | CVE-2008-5100 (CCN-46695) | ||||||||
Assigned: | 2008-11-13 | ||||||||
Published: | 2008-11-13 | ||||||||
Updated: | 2018-10-11 | ||||||||
Summary: | The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 8.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:UR)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Nov 13 2008 - 10:07:33 CST New Whitepaper - .NET Framework Rootkits: Backdoors inside your Framework Source: MITRE Type: CNA CVE-2008-5100 Source: CCN Type: Microsoft MSDN Web site .NET Framework Source: SREASON Type: UNKNOWN 4605 Source: MISC Type: UNKNOWN http://www.applicationsecurity.co.il/.NET-Framework-Rootkits.aspx Source: CCN Type: ApplicationSecurity Web site .NET Framework Rootkits Source: CCN Type: ApplicationSecurity Advisory, November 2008 .NET Framework Rootkits: Backdoors inside your Framework Source: MISC Type: Exploit http://www.applicationsecurity.co.il/LinkClick.aspx?fileticket=ycIS1bewMBI%3d&tabid=161&mid=555 Source: CCN Type: OSVDB ID: 50302 Microsoft .NET Framework Strong Name Implementation DLL File Public Key Token Subversion Multiple Mechanism Authentication Bypass Source: BUGTRAQ Type: UNKNOWN 20081113 New Whitepaper - .NET Framework Rootkits: Backdoors inside your Framework Source: XF Type: UNKNOWN ms-dotnet-sn-weak-security(46695) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |