Microsoft Exchange Server Cross-Site Scripting Vulnerability

Release Date: 15th May 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2008-4250 is a critical remote code execution (RCE) vulnerability in the Microsoft Windows Server Service. The flaw is caused by an improperly handled RPC request resulting in a stack-based buffer overflow.

The vulnerability became widely known through exploitation by the Conficker worm and is associated with Microsoft Security Bulletin MS08-067

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2008-4250
  3. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067
  4. https://support.microsoft.com/en-us/topic/ms08-067-vulnerability-in-server-service-could-allow-remote-code-execution-ac7878fc-be69-7143-472d-2507a179cd15