CVE-2008-4114 is an improper consistency-validation flaw in srv.sys, used by the Microsoft Windows Server service. Affected Windows versions insufficiently validate the relationship between the offset in an SMB WRITE_ANDX request and the packet buffer size. A remote attacker can submit a malformed SMB request, demonstrated against a named-pipe endpoint, whose offset is inconsistent with the supplied packet length, causing the system to crash. The vulnerability affects Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP1 and SP2; Windows Vista Gold and SP1; and Windows Server 2008.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module (modules/auxiliary/dos/windows/smb/ms09_001_write.rb) that exploits a denial of service vulnerability (CVE-2008-4114, MS09-001) in the Microsoft Windows SRV.SYS driver. The exploit works by sending specially crafted SMB packets with invalid DataOffset and DataLenLow fields to the target's SMB service (typically on TCP port 445). The module is written in Ruby and leverages Metasploit's SMB client libraries. When executed, it attempts to crash the remote host's SMB service, resulting in a denial of service. The exploit is a proof-of-concept and does not provide code execution or a shell, only service disruption. The code is structured as a standard Metasploit module with initialization, packet crafting, and a run loop that iterates over various parameter values to trigger the vulnerability. No hardcoded IPs, domains, or file paths are present; the only fingerprintable endpoint is the SMB service port (445) on the target.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability example involving inconsistent validation of input fields, where an offset value inconsistent with packet size can cause a system crash.
Observed example involving an untrusted offset in kernel code.
Packet offset validation failure causing a system crash.
An inconsistent packet offset can cause a system crash.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.