Known vulnerability record

CVE-2008-4250

Microsoft Windows Buffer Overflow Vulnerability

Stable IDcve:CVE-2008-4250Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Keep the signals separate

CVSS severitycriticalScore 9.8 · source CISA-ADP
EPSS probability98.8%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-05-20
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2008-10-23
CVE modified
2026-05-21
KEV date added
2026-05-20
Dataset fetched
2026-08-21T03:55:04.661Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.