CVE-2008-4250CISA KEV
Microsoft Windows Buffer Overflow Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
- Product
- Windows
- Added to KEV
- 20 May 2026
- Federal remediation due
- 3 Jun 2026
- Known ransomware use
- Not reported