Vulnerability record · CVE-2009-3699 · published 15 October 2009
CVE-2009-3699: IBM AIX and VIOS rpc.cmsd XDR string stack buffer overflow
Ibm · Vios
A stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and VIOS 2.1 and earlier. A remote attacker can send a long XDR string as the first argument to procedure 21 of rpc.cmsd, overflowing a stack buffer and potentially executing arbitrary code. The flaw is remotely reachable over the network with no authentication, making it a serious exposure for unpatched systems running the calendar service.
Description
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete impact, plus available exploit code and very high EPSS, makes this a critical risk for unpatched AIX and VIOS systems.
What it is
A stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and VIOS 2.1 and earlier. A remote attacker can send a long XDR string as the first argument to procedure 21 of rpc.cmsd, overflowing a stack buffer and potentially executing arbitrary code. The flaw is remotely reachable over the network with no authentication, making it a serious exposure for unpatched systems running the calendar service.
Impact
An attacker can execute arbitrary code with the privileges of the rpc.cmsd process, which typically runs as root on AIX and VIOS. Successful exploitation can lead to full compromise of the affected host.
Attack surface
The vulnerability is reached over the network via RPC calls to procedure 21 of rpc.cmsd, with no authentication or user interaction required per the CVSS vector AV:N/AC:L/Au:N. Any host that can reach the rpc.cmsd service can attempt the attack.
Exploitation
CVE-2009-3699 is not listed in CISA KEV, but EPSS shows a 30-day exploitation probability of 0.62345 (99.1st percentile), and references include an Exploit tag plus a public Immunity tool, indicating exploit code is available.
What to do
- Apply the IBM AIX and VIOS fixes referenced in the IBM advisories (IZ61628, IZ61717, IZ62123, IZ62237, IZ62569-IZ62572, IZ62672) or the cmsd_advisory.asc efix.
- If rpc.cmsd is not required, disable or stop the calendar daemon and remove it from inetd or the RPC services configuration.
- Restrict network access to rpc.cmsd (TCP/UDP port 100068) using firewalls or network segmentation so only trusted hosts can reach it.
- Monitor IBM security bulletins for updated fixes and re-apply patches if new versions are released.
Detection
- Monitor network traffic for RPC calls to rpc.cmsd procedure 21 containing unusually long XDR strings.
- Check AIX and VIOS systems for the presence of rpc.cmsd and confirm whether it is running and exposed.
- Review system logs and process behavior for crashes or unexpected child processes spawned by rpc.cmsd.
- Use host-based intrusion detection or endpoint monitoring to alert on abnormal rpc.cmsd activity or memory corruption indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3699 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.