CVE-2008-4250 is a low severity vulnerability with a CVSS score of 0.0. Exploits are available; patches have been released and should be applied urgently. This is classified as a zero-day vulnerability.
Very high probability of exploitation in the next 30 days
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
| Vendor | Product |
|---|---|
| Microsoft | Windows Vista |
| Microsoft | Windows Xp |
| Microsoft | Windows 2000 |
| Microsoft | Windows Server 2003 |
| Microsoft | Windows Server 2008 |
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.