CVE-2008-4250

Confirmed PUBLISHED

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows...

Microsoft · Windows

6431 days faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 98.8%

At a Glance

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

cisa windows microsoft
CVE Published
Oct 23, 2008
Exploitation Reported
Oct 23, 2008
CVSS
9.8 Critical
EPSS
98.8%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • SSRT080164 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=122703006921213&w=2
  • MS08-067 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • 32326 secunia.com · Third-Party Advisory http://secunia.com/advisories/32326
  • VU#827267 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/827267
  • TA08-297A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA08-297A.html
Show 13 more references
  • TA09-088A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA09-088A.html
  • 7132 exploit-db.com · Exploit https://www.exploit-db.com/exploits/7132
  • 6841 exploit-db.com · Exploit https://www.exploit-db.com/exploits/6841
  • 6824 exploit-db.com · Exploit https://www.exploit-db.com/exploits/6824
  • 7104 exploit-db.com · Exploit https://www.exploit-db.com/exploits/7104
  • 1021091 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1021091
  • 31874 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/31874
  • ADV-2008-2902 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2008/2902
  • win-server-rpc-code-execution(46040) exchange.xforce.ibmcloud.com · VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/46040
  • oval:org.mitre.oval:def:6093 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • 20081026 Windows RPC MS08-067 FAQ document released securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/497808/100/0/threaded
  • 20081027 Windows RPC MS08-067 FAQ document updated securityfocus.com · Mailing List http://www.securityfocus.com/archive/1/497816/100/0/threaded
  • blogs.securiteam.com/index.php/archives/1150 blogs.securiteam.com · CVE Record http://blogs.securiteam.com/index.php/archives/1150

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.