Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Microsoft Video ActiveX Control Remote Code Execution Vulnerability

IdentifiersCVE-2008-0015CWE-121· Stack-based Buffer Overflow

CVE-2008-0015 is a stack-based buffer overflow in the Active Template Library (ATL) function CComVariant::ReadFromStream, as used by the MPEG2TuneRequest ActiveX control in msvidctl.dll (DirectShow) on Microsoft Windows. A remote attacker can trigger the flaw by causing a user to load specially crafted HTML content, such as a malicious web page, that instantiates the vulnerable ActiveX control and passes crafted data to the control. Affected platforms include legacy Microsoft Windows versions including Windows 2000 SP4, Windows XP SP2/SP3, Windows Server 2003 SP2, Windows Vista Gold/SP1/SP2, and Windows Server 2008 Gold/SP2. Successful exploitation results in arbitrary code execution in the context of the logged-on user. The vulnerability was exploited in the wild, including activity observed in July 2009, and has been referred to as the Microsoft Video ActiveX Control Vulnerability.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows remote, unauthenticated code execution on the target system when a user views attacker-controlled HTML content. The attacker gains execution with the privileges of the logged-on user, which can lead to full compromise where the user has administrative rights. Reported post-exploitation activity included downloading and executing additional malware, including Dogkild, enabling follow-on actions such as persistence, propagation, disabling security tools, modifying the Hosts file, and broader system compromise.

Mitigation

If you can’t patch tonight, do this now.

If patching is not immediately possible, disable the vulnerable ActiveX controls using Microsoft's Fix it/kill-bit guidance from KB972890 / Security Advisory 972890, or otherwise prevent the control from being instantiated. Disabling ActiveX controls in the Internet Zone and restricting use of Internet Explorer or legacy IE-compatibility modes reduces exposure. Additional compensating controls include preventing users from rendering untrusted HTML content and isolating or retiring affected legacy systems.

Remediation

Patch, then assume compromise.

Apply Microsoft's security update for this issue as provided in Security Bulletin MS09-032. Ensure all affected legacy Windows systems receive the vendor patch or are upgraded/replaced if they are no longer supported. Validate that the vulnerable msvidctl.dll/Video ActiveX control is no longer exposed in the affected environment after patching.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationVideo Activex Control (Msvidctl.Dll) / Activex Control For Streaming Videoapplication
Microsoft CorporationWindows 2003 Serveroperating_system
Microsoft CorporationWindows Xpoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware1

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity11

Community discussion across Reddit, Mastodon, and other social sources.