CVE-2008-5100
Estado: ModificadaAlta (10)—
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 8.37%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
- http://securityreason.com/securityalert/4605
- http://www.applicationsecurity.co.il/.NET-Framework-Rootkits.aspx
- http://www.applicationsecurity.co.il/LinkClick.aspx?fileticket=ycIS1bewMBI%3d&tabid=161&mid=555
- http://www.securityfocus.com/archive/1/498311/100/0/threaded
- http://securityreason.com/securityalert/4605
- http://www.applicationsecurity.co.il/.NET-Framework-Rootkits.aspx
- http://www.applicationsecurity.co.il/LinkClick.aspx?fileticket=ycIS1bewMBI%3d&tabid=161&mid=555
- http://www.securityfocus.com/archive/1/498311/100/0/threaded
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-5100",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": true,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-11-17T18:18:47.953",
"references": [
{
"url": "http://securityreason.com/securityalert/4605",
"source": "cve@mitre.org"
},
{
"url": "http://www.applicationsecurity.co.il/.NET-Framework-Rootkits.aspx",
"source": "cve@mitre.org"
},
{
"url": "http://www.applicationsecurity.co.il/LinkClick.aspx?fileticket=ycIS1bewMBI%3d&tabid=161&mid=555",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/498311/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4605",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.applicationsecurity.co.il/.NET-Framework-Rootkits.aspx",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.applicationsecurity.co.il/LinkClick.aspx?fileticket=ycIS1bewMBI%3d&tabid=161&mid=555",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/498311/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs."
},
{
"lang": "es",
"value": "La implementación de strong name (nombre fuerte) (SN) en Microsoft .NET Framework 2.0.50727 confía en la firma digital Public Key Token embebida en la ruta de un archivo DLL en vez de en la firma digital de este mismo archivo, lo que facilita a los atacantes evitar los mecanismos de protección Global Assembly Cache (GAC) y Code Access Security (CAS), también conocidos como MSRC8566gs."
}
],
"lastModified": "2026-06-16T22:59:15.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:.net_framework:2.0.50727:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60D50F4D-1FDD-46C4-B289-7EF93106E44E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}