CVE-2010-3407

IBM Lotus Domino <8.0.2 FP5-8.5.1 FP2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2010-3407. PoCs published by Metasploit, A. Plaskett, A. Plaskett, sinn3r, including Metasploit module exploits/windows/lotus/domino_icalendar_organizer.

AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in IBM Lotus Domino iCalendar via a malformed 'ORGANIZER;mailto' header. It achieves remote code execution by overwriting EIP and leveraging ROP gadgets to bypass DEP on Windows systems.

Description

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17151

This is a Metasploit module exploiting a buffer overflow in IBM Lotus Domino iCalendar via a malformed 'ORGANIZER;mailto' header. It achieves remote code execution by overwriting EIP and leveraging ROP gadgets to bypass DEP on Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: IBM Lotus Domino 8.5
Auth required
Prerequisites: Valid Lotus Domino mailbox account · Network access to TCP port 25 (SMTP)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by A. Plaskett · textremotemultiple
https://www.exploit-db.com/exploits/15005

The exploit demonstrates a stack-based buffer overflow in IBM Lotus Domino's iCalendar email address handling via a crafted email with an overly long ORGANIZER mailto address. The PoC triggers the vulnerability by overwriting the saved return address, leading to arbitrary code execution in the context of the nrouter.exe process.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: IBM Lotus Domino Server 8.0, 8.5
No auth needed
Prerequisites: Valid email address of a Lotus Domino mailbox account · Access to the target's SMTP server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC NORMAL
by A. Plaskett, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/lotus/domino_icalendar_organizer.rb

This Metasploit module exploits a buffer overflow in IBM Lotus Domino iCalendar via a long 'ORGANIZER;mailto' header, leading to remote code execution. It includes multiple targets for different Windows versions and uses ROP techniques to bypass DEP.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: IBM Lotus Domino 8.5
Auth required
Prerequisites: Valid Domino mailbox account · Network access to TCP port 25
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/61790
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2381
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-177/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/43219
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41433
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21446515
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024448
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15005
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/513706/100/0/threaded

Scores

EPSS 0.4148
EPSS Percentile 98.5%

Details

CWE
CWE-119
Status published
Products (11)
ibm/lotus_domino 8.0
ibm/lotus_domino 8.0.1
ibm/lotus_domino 8.0.2
ibm/lotus_domino 8.0.2.1
ibm/lotus_domino 8.0.2.2
ibm/lotus_domino 8.0.2.3
ibm/lotus_domino 8.0.2.4
ibm/lotus_domino 8.5.0
ibm/lotus_domino 8.5.0.1
ibm/lotus_domino 8.5.1
... and 1 more
Published Sep 16, 2010
Tracked Since Feb 18, 2026