← Vulnerability feed

Vulnerability record · CVE-2008-0015 · published 7 July 2009

CVE-2008-0015: Microsoft DirectShow Video ActiveX Control Stack Buffer Overflow

Microsoft · Windows 2003 Server

A stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow. A crafted web page can trigger the overflow and execute arbitrary code on affected Windows versions. The flaw was exploited in the wild in July 2009, making it a confirmed remote code execution issue rather than a theoretical one.

8.8 CVSS 3.1 High CISA KEV since 17 Feb 2026 EPSS 77% · top 0.5% CWE-119 · Memory buffer overflowCWE-121 · Stack-based buffer overflow
8.8CVSS 3.1 base score, v2 9.3
77%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
41References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityConfirmed in-the-wild exploitation, a CISA KEV listing with a near-term due date, and an EPSS score above the 99th percentile make this an urgent remediation item despite the age of the affected platforms.

What it is

A stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow. A crafted web page can trigger the overflow and execute arbitrary code on affected Windows versions. The flaw was exploited in the wild in July 2009, making it a confirmed remote code execution issue rather than a theoretical one.

Impact

An attacker who gets the control instantiated gains arbitrary code execution in the context of the logged-on user. That permits installation of malware, data theft, or further lateral movement on the host.

Attack surface

Reached over the network via a crafted web page that instantiates the vulnerable ActiveX control; the CVSS vector shows no privileges required but user interaction required, so the victim must load the page in a browser that renders the control. No authentication is needed.

Exploitation

Exploitation is confirmed: the description states it was exploited in the wild in July 2009, multiple references carry the Exploit tag, and it is listed in CISA KEV with a 2026-03-10 remediation due date. EPSS is 0.767 (99.5th percentile), indicating high predicted exploitation activity.

What to do

  • Apply the Microsoft security updates MS09-032 and MS09-037, which address the vulnerable ATL and DirectShow control.
  • If patching cannot be completed immediately, apply the vendor workaround in Microsoft Security Advisory 972890, which disables the vulnerable control via the kill-bit registry setting.
  • Disable or restrict ActiveX execution in browsers and enforce the kill-bit for msvidctl.dll across the estate.
  • Retire or isolate Windows 2000 SP4, XP SP2/SP3, Server 2003 SP2, Vista, and Server 2008 Gold/SP2 systems that cannot be patched.
  • Track KEV remediation against the 2026-03-10 due date and confirm closure.

Detection

  • Hunt for processes loading msvidctl.dll, especially browser processes spawning child processes or making unexpected network connections.
  • Monitor for registry changes to the kill-bit (Compatibility Flags) for the MPEG2TuneRequest control that could indicate tampering or re-enabling.
  • Alert on exploit traffic or payload delivery tied to the known exploit references and US-CERT advisories for this CVE.
  • Review proxy and browser logs for visits to pages hosting the crafted ActiveX exploit.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2008-0015 to the Known Exploited Vulnerabilities catalog on 17 February 2026 as " Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 March 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx Broken Link
http://isc.sans.org/diary.html?storyid=6733 Exploit
http://osvdb.org/55651 Broken Link
http://secunia.com/advisories/36187 Broken Link
http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799 Exploit
http://www.iss.net/threats/329.html Exploit
http://www.kb.cert.org/vuls/id/180513 US Government Resource
http://www.microsoft.com/technet/security/advisory/972890.mspx Vendor Advisory
http://www.securityfocus.com/bid/35558 Broken Link
http://www.securityfocus.com/bid/35585 Broken Link
http://www.securitytracker.com/id?1022514 Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-187A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA09-195A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA09-223A.html US Government Resource
http://www.vupen.com/english/advisories/2009/2232 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-032 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6333 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6363 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7436 Broken Link
http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx Broken Link
http://isc.sans.org/diary.html?storyid=6733 Exploit
http://osvdb.org/55651 Broken Link
http://secunia.com/advisories/36187 Broken Link
http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799 Exploit
http://www.iss.net/threats/329.html Exploit
http://www.kb.cert.org/vuls/id/180513 US Government Resource
http://www.microsoft.com/technet/security/advisory/972890.mspx Vendor Advisory
http://www.securityfocus.com/bid/35558 Broken Link
http://www.securityfocus.com/bid/35585 Broken Link
http://www.securitytracker.com/id?1022514 Broken Link
http://www.us-cert.gov/cas/techalerts/TA09-187A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA09-195A.html US Government Resource
http://www.us-cert.gov/cas/techalerts/TA09-223A.html US Government Resource
http://www.vupen.com/english/advisories/2009/2232 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-032 Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6333 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6363 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7436 Broken Link

Track CVE-2008-0015 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2013-3918Microsoft Windows InformationCardSigninHelper ActiveX out-of-bounds writeThe InformationCardSigninHelper ActiveX control in icardie.dll contains an out-of-bounds write that can be triggered by a crafted web page rendered i…KEVEPSS 74%analysed8.8CVE-2011-3402Microsoft Windows TrueType Font Parsing Remote Code ExecutionThe TrueType font parsing engine in win32k.sys on multiple Windows versions fails to properly handle crafted font data, allowing remote code executio…KEVEPSS 78%analysed8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed7.8CVE-2015-1701Microsoft Windows Win32k.sys Local Privilege EscalationWin32k.sys in the Windows kernel-mode drivers fails to properly validate input, allowing a local user to elevate privileges by running a crafted appl…KEVEPSS 56%analysed7.8CVE-2013-5065Microsoft Windows NDProxy.sys kernel local privilege escalationNDProxy.sys in the Windows kernel on Windows XP SP2/SP3 and Server 2003 SP2 fails to properly validate input, letting a local user escalate privilege…KEVEPSS 35%analysed7.8CVE-2013-3660Microsoft Windows win32k EPATHOBJ pointer flaw allows privilege escalationThe EPATHOBJ::pprFlattenRec function in win32k.sys fails to properly initialize a pointer for the next object in a list, letting a local user gain wr…KEVEPSS 39%analysed7.8CVE-2012-0151Microsoft Windows Authenticode Signature Verification PE Digest Validation FlawThe Authenticode Signature Verification function (WinVerifyTrust) in multiple Microsoft Windows versions fails to properly validate the digest of a s…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2008-0015), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.