Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2026-05-20 — agencies required to remediate by 2026-06-03

CVE-2008-4250

CRITICAL

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary…

Published
Oct 23, 2008
Updated
May 21, 2026
Affected
0 pkgs
Patched
None yet
Exploits
14 known

EPSS Exploitation Probability

via FIRST.org ↗
92.1%probability of exploitation in next 30 days
Very High Risk100th percentile0.00%
91.5%92.5%93.6%94.6%94.0%92.1%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

Affected Products

5 products · 18 configurations
OS
windows 2000microsoft
all
OS
windows server 2003microsoft
all
OS
windows server 2008microsoft
all
OS
windows vistamicrosoft
all
OS
windows xpmicrosoft
all
Exploits & PoCs
14

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-7104remotewindows✓ Verified

Microsoft Windows Server - Code Execution (MS08-067)

by Polymorphours · Nov 12, 2008

EDB-6824doswindows✓ Verified

Microsoft Windows Server - Code Execution (PoC) (MS08-067)

by stephen lawler · Oct 23, 2008

EDB-16362remotewindows✓ Verified

Microsoft Windows Server - Service Relative Path Stack Corruption (MS08-067) (Metasploit)

by Metasploit · Jan 21, 2011

EDB-6841remotewindows✓ Verified

Microsoft Windows Server - Universal Code Execution (MS08-067)

by EMM · Oct 26, 2008

EDB-40279remotewindows

Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)

by ohnozzy · Feb 26, 2016

EDB-7132remotewindows✓ Verified

Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)

by Debasis Mohanty · Nov 16, 2008

Frequently Asked Questions

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
O3 Security · Impact-Aware SCA

Is CVE-2008-4250 in your stack?

O3 detects CVE-2008-4250 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.