Vulnerability record · CVE-2008-4250 · published 23 October 2008
CVE-2008-4250: Microsoft Windows Server service RPC path canonicalization buffer overflow
Microsoft · Windows 2000
The Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer and execute arbitrary code. This is the MS08-067 flaw, a remotely reachable, unauthenticated code execution bug in a core Windows service that was exploited in the wild by Gimmiv.A in October 2008.
Description
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution in a core Windows service, with KEV listing, near-maximum EPSS, and public exploit code.
What it is
The Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer and execute arbitrary code. This is the MS08-067 flaw, a remotely reachable, unauthenticated code execution bug in a core Windows service that was exploited in the wild by Gimmiv.A in October 2008.
Impact
A remote attacker can execute arbitrary code with the privileges of the Server service, typically SYSTEM, giving full control of the host. No user interaction or prior authentication is required.
Attack surface
Reached over the network through the SMB/RPC interface exposed by the Windows Server service; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is needed. Any host exposing the service to untrusted networks is directly reachable.
Exploitation
CISA added it to KEV with a due date of 2026-06-03, EPSS 30-day probability is 0.98751 (99.9th percentile), and multiple references carry Exploit tags including Exploit-DB entries, so public exploit code and in-the-wild use are established.
What to do
- Apply Microsoft security bulletin MS08-067 for all affected Windows versions; this is the primary fix.
- Disable or block the Server service (SMB/RPC) on hosts that do not require it, and restrict TCP 139/445 at network boundaries.
- Segment legacy Windows 2000, XP, Server 2003, Vista, and Server 2008 systems away from untrusted networks.
- Retire or isolate end-of-life systems where the MS08-067 patch cannot be applied, per CISA BOD 22-01 guidance.
- Monitor for and block inbound SMB/RPC from untrusted sources at the perimeter.
Detection
- Alert on SMB/RPC traffic to TCP 139/445 from unexpected or external sources.
- Hunt for known MS08-067 exploit signatures and anomalous Server service crashes or restarts.
- Review host logs for unexpected SYSTEM-level process creation following SMB connections.
- Inventory unpatched legacy Windows hosts still exposing the Server service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2008-4250 to the Known Exploited Vulnerabilities catalog on 20 May 2026 as "Microsoft Windows Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 June 2026.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4250 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4250), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.