Vulnerability record · CVE-2008-0015 · published 7 July 2009
CVE-2008-0015: Microsoft DirectShow Video ActiveX Control Stack Buffer Overflow
Microsoft · Windows 2003 Server
A stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow. A crafted web page can trigger the overflow and execute arbitrary code on affected Windows versions. The flaw was exploited in the wild in July 2009, making it a confirmed remote code execution issue rather than a theoretical one.
Description
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityConfirmed in-the-wild exploitation, a CISA KEV listing with a near-term due date, and an EPSS score above the 99th percentile make this an urgent remediation item despite the age of the affected platforms.
What it is
A stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow. A crafted web page can trigger the overflow and execute arbitrary code on affected Windows versions. The flaw was exploited in the wild in July 2009, making it a confirmed remote code execution issue rather than a theoretical one.
Impact
An attacker who gets the control instantiated gains arbitrary code execution in the context of the logged-on user. That permits installation of malware, data theft, or further lateral movement on the host.
Attack surface
Reached over the network via a crafted web page that instantiates the vulnerable ActiveX control; the CVSS vector shows no privileges required but user interaction required, so the victim must load the page in a browser that renders the control. No authentication is needed.
Exploitation
Exploitation is confirmed: the description states it was exploited in the wild in July 2009, multiple references carry the Exploit tag, and it is listed in CISA KEV with a 2026-03-10 remediation due date. EPSS is 0.767 (99.5th percentile), indicating high predicted exploitation activity.
What to do
- Apply the Microsoft security updates MS09-032 and MS09-037, which address the vulnerable ATL and DirectShow control.
- If patching cannot be completed immediately, apply the vendor workaround in Microsoft Security Advisory 972890, which disables the vulnerable control via the kill-bit registry setting.
- Disable or restrict ActiveX execution in browsers and enforce the kill-bit for msvidctl.dll across the estate.
- Retire or isolate Windows 2000 SP4, XP SP2/SP3, Server 2003 SP2, Vista, and Server 2008 Gold/SP2 systems that cannot be patched.
- Track KEV remediation against the 2026-03-10 due date and confirm closure.
Detection
- Hunt for processes loading msvidctl.dll, especially browser processes spawning child processes or making unexpected network connections.
- Monitor for registry changes to the kill-bit (Compatibility Flags) for the MPEG2TuneRequest control that could indicate tampering or re-enabling.
- Alert on exploit traffic or payload delivery tied to the known exploit references and US-CERT advisories for this CVE.
- Review proxy and browser logs for visits to pages hosting the crafted ActiveX exploit.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2008-0015 to the Known Exploited Vulnerabilities catalog on 17 February 2026 as " Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 March 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0015 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0015), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.