Junglewise Threat Intelligence

CVE-2008-0015: Microsoft Windows Video ActiveX Control stack buffer overflow in DirectShow

CVE-2008-0015 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2026-02-17

Technologies: Microsoft Windows 2000, Microsoft Windows, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows XP. Vendors: Microsoft.

Executive brief

A critical vulnerability exists in a Microsoft Windows component used for processing video content. An attacker can exploit this by tricking a user into visiting a malicious website, which could allow the attacker to take full control of the user's computer. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.

Technical details

A stack-based buffer overflow exists in the CComVariant::ReadFromStream function within the Active Template Library (ATL), as utilized by the MPEG2TuneRequest ActiveX control (msvidctl.dll) in DirectShow. The vulnerability is triggered when the control processes a specially crafted stream from a web page. A remote attacker can exploit this by hosting a malicious website and enticing a user to visit it. Successful exploitation allows for arbitrary code execution in the context of the current user. This vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows 2000 SP4
  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista Gold, SP1, SP2
  • Microsoft Windows Server 2008 Gold, SP2

Timeline

  • 2009-07: exploited: First reported exploitation in the wild.
  • 2026-02-17: kev added: Added to CISA Known Exploited Vulnerabilities catalog.

Related threats