A directory traversal vulnerability in the CIM server (CIMListener) of IBM System Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary DLL code. The vulnerability is exploited by sending a specially crafted M-POST request with a /CIMListener/ URI containing directory traversal sequences (..), enabling the loading of a DLL from a remote WebDAV share. The attack leverages port 6988 and requires the malicious DLL to execute code in its initialization routine. The original CVE described only local file loading, but subsequent research demonstrated remote file loading via WebDAV.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module targeting IBM System Director Agent 5.20.3 on Windows systems. The exploit abuses the 'wmicimsv' service to perform arbitrary DLL injection, allowing execution of attacker-controlled code with SYSTEM privileges. The attack leverages the WebDAV Mini-Redirector (WebClient) service on the target, which must be enabled. The module sets up a WebDAV server to serve the malicious DLL payload and uses a crafted M-POST request to the '/CIMListener/' endpoint to trigger the injection. The exploit is operational and provides SYSTEM-level code execution if successful. The code is written in Ruby and follows standard Metasploit module structure, with clear separation of HTTP/WebDAV request handling and payload delivery. The main fingerprintable endpoints are the '/CIMListener/' HTTP path and the UNC path used for DLL delivery. The exploit targets CVE-2009-0880 and is suitable for use in penetration testing or red teaming against vulnerable IBM System Director Agent installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.