CVE-2008-4250Active Exploitation(microsoft / windows_2000)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft windows_2000 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94CWE-119

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_2000
  • windows_server_2003
  • windows_server_2008
  • windows_vista

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days

What's happening

  • Active exploitation reported across 8 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • General: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-21); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
windows_2000windows_server_2003windows_server_2008windows_vistawindows_xp

1 version affected across 5 products

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-03-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-20: 3Mentions · 2026-05-21: 4Mentions · 2026-06-10: 2Mentions · 2026-06-14: 1Mentions · 2026-07-21: 1PoC Mentioned / Linked · 2026-06-10: 1Active Exploitation · 2026-05-20: 2Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-14: 1Active Exploitation · 2026-07-21: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-21: 2Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 2Technical Details · 2026-06-10: 1Technical Details · 2026-06-14: 1Technical Details · 2026-07-21: 103-1405-1505-2005-2106-1006-1407-21
Signal classification4 categories
Active Exploitation
861.5%
General
323.1%
Patch
17.7%
Disclosure
17.7%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-03-141
General1
2026-05-151
General1
2026-05-203
Active Exploitation2General1
2026-05-214
Active Exploitation3Patch1
2026-06-102
Active Exploitation1Disclosure1
2026-06-141
Active Exploitation1
2026-07-211
Active Exploitation1
Full discourse13 posts
  • OS Dev@OSdev_
    Active Exploitation

    One of the most interesting Windows NT kernel bugs is MS08-067 - tracked as CVE-2008-4250 - https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067 The vulnerability was in the Server service ("srvsvc") and was triggered remotely through a crafted RPC request. An unchecked path parsing routine led to a stack buffer overflow, allowing attackers to execute code in kernel-related services without authentication. It became the primary infection vector for the Conficker worm, proving that a single parsing bug could compromise millions of Windows machines worldwide.

    Post summary

    CVE-2008-4250 caused a remote stack buffer overflow in the Windows Server service, enabling kernel-level code execution, and was widely exploited by the Conficker worm to infect millions of systems worldwide.

    07031101.7K
    4.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/20追加) 🛡️No.1594 CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:バッファエラー (CWE-119) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Microsoft Windows の Server service において、細工された RPC リクエストによりパス正規化処理中にオーバーフローが発生し、リモートから任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Windows Server service が稼働していること。 ・攻撃者が対象へネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・リモートで任意のコードを実行される ・影響を受けるシステムを完全に制御される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2008-4250 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2008/ms08-067 🛡️No.1595 CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability =================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:NULL バイトまたは NULL キャラクタの不適切な無害化 (CWE-158) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft DirectX の DirectShow に含まれる QuickTime Movie Parser Filter において、細工された QuickTime メディアファイルにより任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける DirectX/Windows 環境が稼働していること。 ・攻撃者が細工された QuickTime メディアファイルを対象へ到達させること。 ・利用者が当該ファイルを処理すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・細工されたメディアファイルの処理によりシステムが侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は、当時このエクスプロイトコードを使用した限定的なアクティブ攻撃を認識していると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-1537 https://learn.microsoft.com/ja-jp/security-updates/securityadvisories/2009/971778 🛡️No.1596 CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:ヒープベースのバッファオーバーフロー (CWE-122) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe Reader および Acrobat において、細工された PDF の処理によりメモリ破損が発生し、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Adobe Reader または Acrobat が稼働していること。 ・攻撃者が細工された PDF ファイルを対象へ到達させること。 ・利用者が当該 PDF を開くこと。 ✅悪用時影響 ・リモートで任意のコードを実行される ・PDF 処理時のメモリ破損によりシステムを侵害される✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-3459 http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html 🛡️No.1597 CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Internet Explorer 6/7/8 における use-after-free の脆弱性が存在。削除済みオブジェクトに関連するポインタへアクセスさせることで、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・メモリ内オブジェクトの不適切な取り扱いによりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0249 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-002 🛡️No.1598 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Internet Explorer の Peer Objects component(iepeers.dll)における use-after-free の脆弱性が存在。オブジェクト削除後の無効ポインタ参照により、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 (Microsoft Learn) ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・オブジェクト解放後の不正参照によりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0806 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-018 🛡️No.1599 CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability =================================== ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Defender における link following の脆弱性が存在。認証済みの攻撃者により、ローカル上で権限昇格される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ✅攻撃前提条件 ・影響を受ける Microsoft Malware Protection Engine が稼働していること。 ・攻撃者がローカルで認証済み権限を有していること。 ・ローカルで悪用可能な環境であること。 ✅悪用時影響 ・ローカルで権限昇格される ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-41091 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091 🛡️No.1600 CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:リソースの枯渇 (CWE-400) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Microsoft Defender におけるサービス運用妨害の脆弱性が存在。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Microsoft Defender Antimalware Platform が稼働していること。 ・NVD 採点上、攻撃者がネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・サービス運用妨害により可用性へ高い影響が生じる ・Microsoft Defender の動作停止または機能阻害につながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-45498 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post lists seven CVEs added to the CISA Exploited Vulnerability catalog, detailing severity, technical aspects, and vendor patch references. Active exploitation was confirmed for at least one CVE, underscoring the urgency of applying available fixes.

    020626.3K
    43.9K followersView on X
  • Trio Soft inc@triosoftinc
    Active Exploitation

    5 of CISA's 7 new KEV entries date to 2008-2010. CVE-2008-4250 (Conficker). CVE-2010-0249 (Aurora). Two 2026 Microsoft Defender CVEs join them. Your oldest unpatched endpoints are the easiest entry points. #EndpointSecurity #ITAdmin #CyberSecurity #CISA https://t.co/tqCii3yOiF

    Post summary

    The tweet lists CISA KEV entries for several CVEs, indicating these vulnerabilities are being exploited in the wild, while no PoC, exploit code, patch, or technical details are disclosed.

    1002045
    21 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2008-4250: Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

    Post summary

    The text announces a CVE-2008-4250 buffer overflow in Windows Server Service that enables remote code execution via a crafted RPC request. It provides the technical details of the vulnerability but does not mention any PoC, exploit code, patch, or active exploitation.

    1000030
    258 followersView on X
  • Trio Soft inc@triosoftinc
    Patch

    👉 CVE-2008-4250 has been patchable since October 2008. CVE-2010-0249 since January 2010. Both still active in 2026 because fleet patch coverage is the part nobody audits. Trio MDM shows you exactly where the gap is.

    Post summary

    The post highlights that CVE-2008-4250 and CVE-2010-0249 have been patched since 2008 and 2010 respectively, yet remain active due to inadequate patch audits, and promotes Trio MDM to identify coverage gaps.

    0001032
    21 followersView on X
  • Systemctl@TheNetworkGhost
    Active Exploitation

    🚨 Windows'ta Kritik Güvenlik Açığı: CVE-2008-4250 📅 20 Mayıs 2026 · 03:00 (TR) CISA, oldukça eski bir Windows açığı olan CVE-2008-4250'yi aktif istismar riski nedeniyle KEV listesine dahil etti. Sistemlerinizi korumak için üretici tarafından sağlanan yamaları vakit kaybetmeden uygulamalı ve bulut hizmetleri için BOD 22-01 kılavuzuna uygun hareket etmelisiniz. Eğer gerekli güncellemeler yapılamıyorsa, riskli sistemlerin kullanımına son verilmesi güvenlik açısından kritik önem taşımaktadır.

    Post summary

    CISA has added the long‑standing Windows flaw CVE‑2008‑4250 to the KEV list because it is being actively exploited. Organizations are urged to apply vendor patches urgently or follow BOD 22‑01 guidance to mitigate the risk.

    1000015
    78 followersView on X
  • ThreatLevel@ThreatLevelAI
    Active Exploitation

    🚨 Remote Code Execution in Windows added to the CISA Known Exploited Vulnerabilities catalog (CVE-2008-4250). Active exploitation confirmed. Patch immediately. More details 👇 https://t.co/VbFDnIzSvm

    Post summary

    CISA has added CVE-2008-4250 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a Remote Code Execution flaw in Windows and urging users to apply the patch immediately.

    1000029
    7 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text is merely a list of Windows CVE identifiers with no additional context or details provided.

    10000106
    15 followersView on X
  • FGCBoomers | GodofGrunts@GodofGrunts
    General

    @shaogens @Adriksh Still a better chance of it getting discovered in open source than closed source. CVE-2008-4250 which we never really found out the origin of and was probably a state sponsored attack, was available in Windows for over 8 years

    Post summary

    The tweet briefly notes that CVE-2008-4250 existed in Windows for many years but offers no technical details, PoC, or evidence of exploitation.

    1000069
    370 followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability CVE-2009- @CISACyber

    Post summary

    CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation, including CVE-2008-4250, a Windows buffer overflow flaw.

    0000057
    1.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2008-4250-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link indicates that CVE-2008-4250 is being actively exploited on Windows, suggesting the availability of a PoC, but the text contains no specific exploit code, patch information, or detailed technical description.

    0000021
    258 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (May 20) CVE-2008-4250 Microsoft Windows バッファオーバーフローの脆弱性 CVE-2009-1537 Microsoft DirectXのNULLバイト上書きの脆弱性 CVE-2009-3459 Adobe AcrobatおよびReaderのヒープベースのバッファオーバーフローの脆弱性 CVE-2010-0249 Microsoft Internet ExplorerのUse-After-Free脆弱性 CVE-2010-0806 Microsoft Internet ExplorerのUse-After-Free脆弱性 CVE-2026-41091 Microsoft Defenderの特権昇格の脆弱性 CVE-2026-45498 Microsoft Defenderのサービス拒否攻撃の脆弱性 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced the addition of seven CVEs, all known to have been exploited, but the post does not provide exploit code or patch details.

    00000256
    4.8K followersView on X
  • DailyCVE@dailycve
    General

    🔴 #Windows, Remote Code Execution, #CVE-2008-4250 (Critical) https://dailycve.com/windows-remote-code-execution-cve-2008-4250-critical/

    Post summary

    A brief announcement of a critical Windows Remote Code Execution vulnerability (CVE‑2008‑4250) with a link to a daily CVE article, but no detailed information on PoC, exploits, or mitigation.

    0000046
    206 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_2000---
OSmicrosoftwindows_server_2003--x64
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2003--itanium
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2003--itanium
OSmicrosoftwindows_server_2003--x64
OSmicrosoftwindows_server_2008--itanium
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_vista---
OSmicrosoftwindows_vista--x64
OSmicrosoftwindows_vista---
OSmicrosoftwindows_vista--x64
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp---
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp---

Explore more