CVE-2008-4250
KEVmassRemote Code Execution Buffer Overflow in Microsoft Windows Server Service
CISA: Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows contains a buffer overflow in the Windows Server Service that is triggered when a specially crafted RPC request causes an overflow during path canonicalization. A remote attacker who can reach the service (historically over SMB) can send such a request and execute arbitrary code on the target system. Any Microsoft Windows system running the Server Service is affected, with exposure concentrated on legacy or unpatched machines whose RPC/SMB interface is reachable from untrusted networks. CISA added the flaw (CVE-2008-4250, the vulnerability addressed by Microsoft's 2008 MS08-067 bulletin) to its Known Exploited Vulnerabilities catalog on 2026-05-20, confirming exploitation in the wild, with no ransomware association yet documented. Its EPSS score of 98.8% (100th percentile) indicates a very high likelihood of continued exploitation over the next 30 days.
What to do: Confirm that every Windows host has the Server Service fix from Microsoft bulletin MS08-067 (released October 2008) or a later Windows update, prioritizing internet-facing and legacy systems that may never have been patched. Restrict inbound SMB/RPC (TCP 445) to trusted networks, disable the Server Service where it is not required, and hunt for indicators of compromise on unpatched hosts. Federal agencies must apply mitigations per vendor instructions and applicable BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable, per the KEV required action.
| Microsoft Windows (Server Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-94