CVE-2008-4250
Description
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka 'Server Service Vulnerability.'
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 75 Days)
Improper Control of Generation of Code ('Code Injection')
DraftCommon Consequences
Applicable Platforms
Microsoft Windows Server - Code Execution (PoC) (MS08-067)
VerifiedMicrosoft Windows Server - Code Execution (PoC) (MS08-067)
View Exploit Code →Microsoft Windows Server - Universal Code Execution (MS08-067)
VerifiedMicrosoft Windows Server - Universal Code Execution (MS08-067)
View Exploit Code →Microsoft Windows Server - Code Execution (MS08-067)
VerifiedMicrosoft Windows Server - Code Execution (MS08-067)
View Exploit Code →Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
VerifiedMicrosoft Windows Server 2000/2003 - Code Execution (MS08-067)
View Exploit Code →Microsoft Windows Server - Service Relative Path Stack …
Verified Metasploit Framework (MSF)Microsoft Windows Server - Service Relative Path Stack Corruption (MS08-067) (Metasploit)
View Exploit Code →Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
View Exploit Code →Windows Server 2008 by Microsoft
cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:-:*:x86:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*
Windows Xp by Microsoft
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*
Windows Vista by Microsoft
cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*
Windows Server 2008 by Microsoft
cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:-:*:x64:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:*:*:*:*
Windows Xp by Microsoft
cpe:2.3:o:microsoft:windows_xp:-:-:*:*:professional:*:x64:*
Windows Vista by Microsoft
cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:x64:*
Windows Vista by Microsoft
cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*
Windows Server 2008 by Microsoft
cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:-:*:itanium:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:sp1:*:*:-:*:itanium:*
Windows Vista by Microsoft
cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:-:*:x64:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:itanium:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:x64:*
Windows Xp by Microsoft
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:x64:*
Windows Xp by Microsoft
cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*
Windows 2000 by Microsoft
cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*
Windows Server 2003 by Microsoft
cpe:2.3:o:microsoft:windows_server_2003:-:*:*:*:*:*:x64:*