10

CVE-2008-4250

Warnung
Medienbericht
Exploit
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
Microsoft ≫ Windows Server 2003 Version - Update sp1
Microsoft ≫ Windows Server 2003 Version - Update sp1 SwEdition - HwPlatform itanium
Microsoft ≫ Windows Server 2003 Version - Update sp2
Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform itanium
Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform x64
Microsoft ≫ Windows Server 2008 Version - SwEdition - HwPlatform itanium
Microsoft ≫ Windows Server 2008 Version - SwEdition - HwPlatform x64
Microsoft ≫ Windows Server 2008 Version - SwEdition - HwPlatform x86
Microsoft ≫ Windows Vista Version -
Microsoft ≫ Windows Vista Version - HwPlatform x64
Microsoft ≫ Windows Vista Version - Update sp1
Microsoft ≫ Windows Vista Version - Update sp1 SwEdition - HwPlatform x64
Microsoft ≫ Windows Xp Version - Update - SwEdition professional HwPlatform x64
Microsoft ≫ Windows Xp Version - Update sp2
Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
Microsoft ≫ Windows Xp Version - Update sp3

20.05.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows Buffer Overflow Vulnerability

Schwachstelle

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 98.75% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
21.05.2026 14:09
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
21.05.2026 08:24
http://marc.info/?l=bugtraq&m=122703006921213&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://blogs.securiteam.com/index.php/archives/1150
Permissions Required
http://secunia.com/advisories/32326
Patch
Vendor Advisory
http://www.kb.cert.org/vuls/id/827267
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/497808/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/archive/1/497816/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/31874
Patch
Third Party Advisory
Exploit
Broken Link
VDB Entry
http://www.securitytracker.com/id?1021091
Third Party Advisory
Broken Link
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA08-297A.html
Third Party Advisory
US Government Resource
Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-088A.html
Third Party Advisory
US Government Resource
http://www.vupen.com/english/advisories/2008/2902
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/46040
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6093
Third Party Advisory
Broken Link
https://www.exploit-db.com/exploits/6824
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/6841
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/7104
Third Party Advisory
Exploit
VDB Entry
https://www.exploit-db.com/exploits/7132
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4250
US Government Resource