Vulnerability record · CVE-2008-5180 · published 20 November 2008
CVE-2008-5180: Microsoft Communicator SIP INVITE flood causes memory exhaustion DoS
Microsoft · Office Communicator
Microsoft Communicator, including the version bundled in the Office 2010 beta, allocates a session for each incoming SIP INVITE without limiting how many can be created. A remote sender can flood INVITE requests to drive unbounded memory consumption and degrade or crash the client. The flaw is a classic missing-allocation-limit issue (CWE-770).
Description
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Automated analysis
medium priorityRemote, unauthenticated and publicly exploitable, but impact is limited to availability (CVSS 5.3) and the affected product is long out of support.
What it is
Microsoft Communicator, including the version bundled in the Office 2010 beta, allocates a session for each incoming SIP INVITE without limiting how many can be created. A remote sender can flood INVITE requests to drive unbounded memory consumption and degrade or crash the client. The flaw is a classic missing-allocation-limit issue (CWE-770).
Impact
An unauthenticated remote attacker can exhaust memory on the target Communicator client, causing denial of service for that user's voice, IM and presence functions. The CVSS vector scores availability impact as Low, so full host compromise is not indicated.
Attack surface
Reachable over the network via SIP traffic to the Communicator client; the CVSS vector shows no privileges and no user interaction required. The attacker only needs to be able to send SIP INVITE requests to the endpoint.
Exploitation
Public exploit code exists (Exploit-DB entries 7262 and 12079), and EPSS is high at roughly 0.68 (99th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the vendor fix for Microsoft Communicator; if the product is end-of-life, migrate to a supported client.
- Restrict SIP reachability to trusted servers and networks using firewall rules and SIP-aware filtering.
- Rate-limit or drop excessive SIP INVITE traffic at the perimeter or session border controller.
- Monitor client memory use and restart or isolate clients that show abnormal session growth.
Detection
- Alert on spikes in SIP INVITE volume or concurrent session counts per client.
- Monitor Communicator client processes for abnormal memory growth or repeated crashes.
- Review perimeter and SBC logs for INVITE floods from single or spoofed sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-5180 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-5180), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.