PT-2008-6247 · Microsoft · .Net Framework
Erez Metula
·
Publicado
2008-11-17
·
Atualizado
2018-10-11
·
CVE-2008-5100
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework version 2.0.50727
Description
The issue concerns the strong name implementation in Microsoft .NET Framework, which relies on the digital signature Public Key Token in the pathname of a DLL file. This makes it easier for attackers to bypass protection mechanisms such as Global Assembly Cache (GAC) and Code Access Security (CAS).
Recommendations
For Microsoft .NET Framework version 2.0.50727, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
.Net Framework