CVE-2009-0880

IBM Director < 5.20.3 - Remote Code Execution via CIM Server Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2009-0880. PoCs published by Metasploit, Bernhard Mueller, kingcope, including Metasploit module exploits/windows/misc/ibm_director_cim_dllinject.

AI-analyzed exploit summary This Metasploit module exploits a DLL injection vulnerability in IBM System Director Agent 5.20.3 via WebDAV to achieve remote code execution with SYSTEM privileges. It leverages the WebClient service to deliver a malicious DLL payload.

Description

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/23203

This Metasploit module exploits a DLL injection vulnerability in IBM System Director Agent 5.20.3 via WebDAV to achieve remote code execution with SYSTEM privileges. It leverages the WebClient service to deliver a malicious DLL payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM System Director Agent 5.20.3
No auth needed
Prerequisites: WebClient service enabled on target · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Bernhard Mueller · perllocalwindows
https://www.exploit-db.com/exploits/32845

This exploit targets a privilege escalation vulnerability in IBM Director's CIM server by sending a malformed XML payload via HTTP to trigger arbitrary code execution with elevated privileges. The PoC constructs a malicious CIM ExportIndication request to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IBM Director < 5.20.3 Service Update 2
No auth needed
Prerequisites: Network access to the target's CIM server (port 6988)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by kingcope · textremotewindows
https://www.exploit-db.com/exploits/23074

This exploit leverages CVE-2009-0880 to force IBM System Director to load a DLL from a remote WebDAV share, achieving remote code execution. The PoC sends a crafted XML payload via HTTP to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM System Director versions 5.20.3 and before
No auth needed
Prerequisites: Network access to port 6988 · Remote WebDAV share hosting the malicious DLL
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Bernhard Mueller, kingcope, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ibm_director_cim_dllinject.rb

This Metasploit module exploits a DLL injection vulnerability in IBM System Director Agent 5.20.3 by leveraging a WebDAV service to achieve arbitrary code execution with SYSTEM privileges. It handles WebDAV requests (OPTIONS, PROPFIND, GET) to serve a malicious DLL payload to the target.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM System Director Agent 5.20.3
No auth needed
Prerequisites: WebClient service (WebDAV Mini-Redirector) enabled on the target · Network access to the target's CIMListener service (port 6988)
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0656
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/52616
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/501639/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34065
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34212
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49286

Scores

EPSS 0.3160
EPSS Percentile 98.1%

Details

CWE
CWE-22
Status published
Products (15)
ibm/director 3.1.1
ibm/director 4.10
ibm/director 4.11
ibm/director 4.12
ibm/director 4.20
ibm/director 4.21
ibm/director 4.22
ibm/director 5.10.0
ibm/director 5.10.1
ibm/director 5.10.2
... and 5 more
Published Mar 12, 2009
Tracked Since Feb 18, 2026