First published: Thu Nov 20 2008(Updated: )
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Communicator |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5180 is classified as a denial of service vulnerability that can significantly impact system availability.
To mitigate CVE-2008-5180, ensure that you are running the latest version of Microsoft Office Communicator with all security updates applied.
Symptoms of CVE-2008-5180 exploitation include unexpected system slowdowns or crashes due to excessive memory consumption.
Users of Microsoft Office Communicator, specifically those running the 2010 beta version, are affected by CVE-2008-5180.
Yes, CVE-2008-5180 can be exploited remotely through the sending of a large number of SIP INVITE requests.