CVE-2008-4250

Properties

Published:
22.10.2008
Updated:
29.10.2008
Patch available:
Severity:
High
CVSS vector:
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Product:
microsoft: windows_xp
microsoft: windows_xp

Vulnerability description

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

References:

CERT-VN: http://www.kb.cert.org/vuls/id/827267
MS: http://www.microsoft.com/technet/security/Bulletin/ms08-067.mspx
SECUNIA: http://secunia.com/advisories/32326
XF: http://xforce.iss.net/xforce/xfdb/46040
FRSIRT: http://www.frsirt.com/english/advisories/2008/2902