← Vulnerability feed

Vulnerability record · CVE-2013-0536 · published 21 June 2013

CVE-2013-0536: Ibm lotus inotes permissions and access controls vulnerability

Ibm · Lotus Inotes

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

7.2 CVSS 2.0 High EPSS 0.37% · top 71.5% CWE-264 · Permissions and access controls
7.2CVSS 2.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0536 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-1608Ibm lotus notes memory buffer overflow vulnerabilityStack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unk…EPSS 5.8%10.0CVE-2009-3032Ibm lotus notes vulnerabilityInteger overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security f…EPSS 3.7%10.0CVE-2010-0918Ibm lotus inotes vulnerabilityMultiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.…EPSS 2.1%10.0CVE-2009-4594Ibm lotus inotes vulnerabilityUnspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, a…EPSS 1.5%10.0CVE-2010-0274Ibm lotus inotes vulnerabilityUnspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino …EPSS 1.5%10.0CVE-2010-0275Ibm lotus inotes vulnerabilityUltra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in t…EPSS 1.5%10.0CVE-2010-0276Ibm domino web access vulnerabilityIBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyw…EPSS 1.5%10.0CVE-2006-0119Ibm lotus domino vulnerabilityMultiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential secu…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2013-0536), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.