← Vulnerability feed

Vulnerability record · CVE-2008-2499 · published 29 May 2008

CVE-2008-2499: IBM Lotus Sametime MUX stack buffer overflow via crafted URL

Ibm · Lotus Sametime

The Community Services Multiplexer (StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, contains a stack-based buffer overflow (CWE-119) triggered by a crafted URL. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the affected system.

7.5 CVSS 2.0 High EPSS 77% · top 0.5% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote unauthenticated code execution with a very high EPSS score and public exploit reference, though not in KEV.

What it is

The Community Services Multiplexer (StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, contains a stack-based buffer overflow (CWE-119) triggered by a crafted URL. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the affected system.

Impact

Successful exploitation allows remote code execution with the privileges of the vulnerable service, potentially leading to full compromise of the host. The CVSS 2.0 vector (AV:N/AC:L/Au:N/C:P/I:P/A:P) indicates partial confidentiality, integrity, and availability impact.

Attack surface

The flaw is reachable over the network via a crafted URL processed by the MUX component; no authentication is required per the CVSS vector (Au:N). No user interaction is indicated in the description or vector.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.77466, 99.5th percentile) and a reference is tagged 'Exploit', indicating public exploit information exists. No ransomware associations are documented.

What to do

  • Apply the vendor patch or upgrade to IBM Lotus Sametime 8.0.1 or later as directed by IBM advisory swg21303920.
  • If immediate patching is not possible, restrict network access to the MUX service (StMux.exe) to trusted hosts only.
  • Monitor and filter crafted URLs directed at the Sametime MUX component at network boundaries.
  • Review IBM's advisory and any available workarounds for interim risk reduction.

Detection

  • Inspect network traffic for malformed or unusually long URLs targeting the Sametime MUX service.
  • Monitor host logs for crashes or abnormal process behavior in StMux.exe.
  • Use endpoint detection to flag buffer overflow exploitation patterns (e.g., unexpected code execution from the MUX process).

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-3398Ibm lotus sametime vulnerabilityUnspecified vulnerability in the webcontainer implementation in IBM Lotus Sametime Connect 8.5.1 before CF1 has unknown impact and attack vectors, ak…EPSS 1.4%9.3CVE-2007-1784Ibm lotus sametime vulnerabilityThe JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL librari…EPSS 3.5%5.0CVE-2011-1370Ibm lotus sametime vulnerabilityThe default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authen…EPSS 1.1%4.3CVE-2013-3986Ibm lotus sametime memory buffer overflow vulnerabilityIBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Vis…EPSS 9.3%4.3CVE-2011-1106Ibm lotus sametime cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to inject arbitrary web script o…EPSS 1.5%4.3CVE-2011-1038Ibm lotus sametime cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote attackers to inject arbitrar…EPSS 3.1%4.3CVE-2008-0354Ibm lotus sametime cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbit…EPSS 2.9%4.3CVE-2007-6295Ibm lotus sametime cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the WebRunMenuFrame page in the online meeting center template in IBM Lotus Sametime before 8.0 allows re…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2008-2499), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.