← Back

CVE-2008-4114

nvd nist
Published: Sep 16, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:C
Exploitability: 8.6 / Impact: 6.9
Source: NVD

Description

srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."

Affected (16)

5 products
Windows 2000
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microsoft
All versions
All versions
All versions
All versions
Microsoft
All versions
All versions
All versions
Microsoft
All versions
All versions
Version gold
Version sp1
Microsoft
All versions
All versions
All versions
All versions

Related CWEs

References (26)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.