Microsoft Office Remote Code Execution - Active in CISA KEV catalog.
Description
Microsoft Office Remote Code Execution - Active in CISA KEV catalog.
Remediation
FEDERAL DEADLINE: April 27, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: April 27, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA KEV Details
Deadline: April 27, 2026
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
---METADATA---
VENDOR: Microsoft
PRODUCT: Windows
AFFECTED_VERSIONS: Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A buffer overflow in the Windows Server service allows unauthenticated remote code execution via specially crafted RPC requests.
Executive Summary:
This critical buffer overflow in the Windows Server service is confirmed to be actively exploited and presents a significant risk of wormable remote code execution.
Vulnerability Details
CVE-ID: CVE-2008-4250
Affected Software: Microsoft Windows
Affected Versions: Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta.
Vulnerability: This is a buffer overflow in the Server service (RPC). The vulnerability is unauthenticated and can be triggered remotely without user interaction, making it highly dangerous.
Business Impact
The CVSS score of 9.5 reflects the potential for total system compromise. Because it is wormable on older systems, a single infection can lead to rapid lateral movement across a network, causing widespread downtime and catastrophic data loss.
Remediation Plan
Immediate Action: Apply the patch provided in Microsoft Security Bulletin MS08-067 immediately.
Proactive Monitoring: Monitor network traffic for anomalous RPC traffic and utilize IDS/IPS signatures to detect attempts to exploit the Server service.
Compensating Controls: Restrict access to ports associated with RPC (specifically TCP 445) at the network perimeter and host-based firewalls to prevent remote reachability of the vulnerable service.
Exploitation Status
Public Exploit Available: Yes — Metasploit modules and multiple ExploitDB entries are available.
Analyst Notes: This vulnerability is confirmed to be actively exploited in the wild as of May 20, 2026. Despite its age, it remains a common target for threat actors targeting unpatched legacy infrastructure.
Analyst Recommendation
This vulnerability is exceptionally dangerous due to its potential for worm-like propagation. Organizations must ensure all affected systems are patched or isolated from the network to prevent unauthorized access and lateral movement.