peter bassill · operator
$ cve CVE-2008-0015 JSON

CVE-2008-0015 KEV EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 76.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-03-10.

Description

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS76.73% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2026-03-10
Public exploityes
Published2009-07-07
Last modified2026-06-16

CISA KEV

Name Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Added2026-02-17
Due2026-03-10
Vendor / productMicrosoft / Windows
Ransomware usenone reported

Affected (2)

VendorProduct
microsoftwindows 2003 server
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD