CVE-2008-4250
CRITICALThe Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
Affected Products
windows 2000microsoftwindows server 2003microsoftwindows server 2008microsoftwindows vistamicrosoftwindows xpmicrosoftResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Microsoft Windows Server - Code Execution (MS08-067)
by Polymorphours · Nov 12, 2008
Microsoft Windows Server - Code Execution (PoC) (MS08-067)
by stephen lawler · Oct 23, 2008
Microsoft Windows Server - Service Relative Path Stack Corruption (MS08-067) (Metasploit)
by Metasploit · Jan 21, 2011
Microsoft Windows Server - Universal Code Execution (MS08-067)
by EMM · Oct 26, 2008
Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
by ohnozzy · Feb 26, 2016
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
by Debasis Mohanty · Nov 16, 2008
Frequently Asked Questions
Is CVE-2008-4250 in your stack?
O3 detects CVE-2008-4250 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.