CVE-2004-2761 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 9.9% (pctl 95)
Patch early
A public exploit exists.
Description
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.93% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-310 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-01-05 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| ietf | md5 |
| ietf | x.509 certificate |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MD5 - Message Digest Algorithm Hash Collision | 2004-12-07 |
References
- http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/
- http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx
- http://secunia.com/advisories/33826
- http://secunia.com/advisories/34281
- http://secunia.com/advisories/42181
- http://securityreason.com/securityalert/4866
- http://securitytracker.com/id?1024697
- http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html
- http://www.doxpara.com/research/md5/md5_someday.pdf
- http://www.kb.cert.org/vuls/id/836068
- http://www.microsoft.com/technet/security/advisory/961509.mspx
- http://www.phreedom.org/research/rogue-ca/
- http://www.securityfocus.com/archive/1/499685/100/0/threaded
- http://www.securityfocus.com/bid/33065
- http://www.ubuntu.com/usn/usn-740-1
- http://www.win.tue.nl/hashclash/SoftIntCodeSign/
- http://www.win.tue.nl/hashclash/rogue-ca/
- https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php
- https://bugzilla.redhat.com/show_bug.cgi?id=648886
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935
→ the Explorer · watch your stack · NVD