ZeroHour

CVE-2008-4250

KEVmass

Remote Code Execution Buffer Overflow in Microsoft Windows Server Service

CISA: Microsoft Windows Buffer Overflow Vulnerability

CVSS
EPSS
99%p100
Published
KEV added
AI analysis

Microsoft Windows contains a buffer overflow in the Windows Server Service that is triggered when a specially crafted RPC request causes an overflow during path canonicalization. A remote attacker who can reach the service (historically over SMB) can send such a request and execute arbitrary code on the target system. Any Microsoft Windows system running the Server Service is affected, with exposure concentrated on legacy or unpatched machines whose RPC/SMB interface is reachable from untrusted networks. CISA added the flaw (CVE-2008-4250, the vulnerability addressed by Microsoft's 2008 MS08-067 bulletin) to its Known Exploited Vulnerabilities catalog on 2026-05-20, confirming exploitation in the wild, with no ransomware association yet documented. Its EPSS score of 98.8% (100th percentile) indicates a very high likelihood of continued exploitation over the next 30 days.

What to do: Confirm that every Windows host has the Server Service fix from Microsoft bulletin MS08-067 (released October 2008) or a later Windows update, prioritizing internet-facing and legacy systems that may never have been patched. Restrict inbound SMB/RPC (TCP 445) to trusted networks, disable the Server Service where it is not required, and hunt for indicators of compromise on unpatched hosts. Federal agencies must apply mitigations per vendor instructions and applicable BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable, per the KEV required action.

Affected
Microsoft Windows (Server Service)
Estimated exposure
massMillions of Windows systems in total; likely hundreds of thousands of internet-exposed SMB hosts, many on legacy or unpatched machines — Windows holds near-ubiquitous desktop and server market share, and repeated public internet-wide scans have shown hundreds of thousands of exposed SMB/445 endpoints, a substantial share of which are legacy systems that may lack this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-94

In the news