CVE-2008-4250 is a critical remote code execution vulnerability affecting the Server service in various Microsoft Windows operating systems, including Windows 2000, XP, Server 2003, Vista, and Server 2008. It allows unauthenticated attackers to execute arbitrary code by sending a specially crafted RPC request that exploits an overflow during path canonicalization. With a CVSS score of 10.0, this vulnerability is extremely severe, requiring no authentication and having a low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This flaw was actively exploited in the wild by Gimmiv.A in October 2008, with multiple public exploits available, including Metasploit modules, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:-:*:itanium:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.