← Vulnerability feed

Vulnerability record · CVE-2008-5180 · published 20 November 2008

CVE-2008-5180: Microsoft Communicator SIP INVITE flood causes memory exhaustion DoS

Microsoft · Office Communicator

Microsoft Communicator, including the version bundled in the Office 2010 beta, allocates a session for each incoming SIP INVITE without limiting how many can be created. A remote sender can flood INVITE requests to drive unbounded memory consumption and degrade or crash the client. The flaw is a classic missing-allocation-limit issue (CWE-770).

5.3 CVSS 3.1 Medium EPSS 68% · top 0.7% CWE-770 · Allocation without limits
5.3CVSS 3.1 base score, v2 5.0
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityRemote, unauthenticated and publicly exploitable, but impact is limited to availability (CVSS 5.3) and the affected product is long out of support.

What it is

Microsoft Communicator, including the version bundled in the Office 2010 beta, allocates a session for each incoming SIP INVITE without limiting how many can be created. A remote sender can flood INVITE requests to drive unbounded memory consumption and degrade or crash the client. The flaw is a classic missing-allocation-limit issue (CWE-770).

Impact

An unauthenticated remote attacker can exhaust memory on the target Communicator client, causing denial of service for that user's voice, IM and presence functions. The CVSS vector scores availability impact as Low, so full host compromise is not indicated.

Attack surface

Reachable over the network via SIP traffic to the Communicator client; the CVSS vector shows no privileges and no user interaction required. The attacker only needs to be able to send SIP INVITE requests to the endpoint.

Exploitation

Public exploit code exists (Exploit-DB entries 7262 and 12079), and EPSS is high at roughly 0.68 (99th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Apply the vendor fix for Microsoft Communicator; if the product is end-of-life, migrate to a supported client.
  • Restrict SIP reachability to trusted servers and networks using firewall rules and SIP-aware filtering.
  • Rate-limit or drop excessive SIP INVITE traffic at the perimeter or session border controller.
  • Monitor client memory use and restart or isolate clients that show abnormal session growth.

Detection

  • Alert on spikes in SIP INVITE volume or concurrent session counts per client.
  • Monitor Communicator client processes for abnormal memory growth or repeated crashes.
  • Review perimeter and SBC logs for INVITE floods from single or spoofed sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/32940 Broken Link
http://www.exploit-db.com/exploits/12079 ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/39221 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021294 Broken LinkThird Party AdvisoryVDB Entry
http://www.voipshield.com/research-details.php?id=133 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/46673 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/57581 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/7262 ExploitThird Party AdvisoryVDB Entry
http://secunia.com/advisories/32940 Broken Link
http://www.exploit-db.com/exploits/12079 ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/39221 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1021294 Broken LinkThird Party AdvisoryVDB Entry
http://www.voipshield.com/research-details.php?id=133 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/46673 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/57581 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/7262 ExploitThird Party AdvisoryVDB Entry

Track CVE-2008-5180 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2013-1302Microsoft lync memory buffer overflow vulnerabilityMicrosoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote att…EPSS 22%7.5CVE-2008-3068Microsoft access vulnerabilityMicrosoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) …EPSS 17%5.0CVE-2008-5179Microsoft office communications server vulnerabilityUnspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to…EPSS 16%5.0CVE-2008-5181Microsoft office communicator vulnerabilityMicrosoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numb…EPSS 13%4.3CVE-2012-2520Microsoft groove server cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, Shar…EPSS 28%4.3CVE-2012-1858Microsoft lync information exposure vulnerabilityThe toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does …EPSS 22%8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2008-5180), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.