CVE-2015-2474: Microsoft Windows Server 2008

High severity, CVSS 9.0. EPSS: 30.5% chance of exploitation in the next 30 days.

Microsoft Windows Vista SP2 and Server 2008 SP2 allow remote authenticated users to execute arbitrary code via a crafted string in a Server Message Block (SMB) server error-logging action, aka "Server Message Block Memory Corruption Vulnerability."

Affected products

  • Microsoft Windows Server 2008: any version
  • Microsoft Windows Vista: affected versions not specified

Published 2015-08-15. Last modified 2026-06-17.