s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2008-0015 high

📛 Threat Title

Microsoft Windows: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Category: exploited-vulnerability Published: Source updated: First seen: Last updated: Source: CISA KEVCISA Known Exploited Vulnerabilities

Description

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Added to KEV: 2026-02-17. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-10.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2008-0015

IOC database

Type
cve
Value
CVE-2008-0015
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • CISA notes reference CISA KEV
  • NVD detail: CVE-2008-0015 CISA Known Exploited Vulnerabilities

    Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

Remediations (9)

  • web:cyberpress.org

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) vulnerability in the Microsoft Windows Video ActiveX Control to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2008-0015 , this flaw, originally disclosed nearly two decades ago, now confirms active exploitation in the wild. CISA updated the catalog on February 17 ...

  • web:cybersecuritynews.com

    A long-dormant Microsoft Windows vulnerability, CVE-2008-0015 , has been added to the Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw, first disclosed more than a decade ago, impacts the Windows Video ActiveX Control component and poses a serious Remote Code Execution (RCE) risk. According to CISA, attackers are exploiting the ...

  • web:nvd.nist.gov

    You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://nvd.nist.gov

  • web:wnesecurity.com

    Mitigation and Remediation For CVE-2008-0015 The most effective remediation is to apply Microsoft's security updates that disable the vulnerable ActiveX control in Internet Explorer and address related ATL-affected components.

  • web:www.tenable.com

    Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited ...

  • web:www.cve.org

    Vulnerability detail for CVE-2008-0015 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.

  • web:www.microsoft.com

    By preventing the Microsoft Video ActiveX Control from running in Internet Explorer, there is no impact to application compatibility. Additionally, see Microsoft Security Advisory 972890 for more information on mitigation and workarounds.

  • web:www.techepages.com

    If patch cannot be installed, it is recommended to stop using these legacy systems after the due date. What Windows versions are affected by CVE-2008-0015 ? The following Microsoft platforms are affected by CVE-2008-0015 : Microsoft Windows 2000 SP4 Windows XP SP2 and SP3 Windows Server 2003 SP2 Windows Vista (Gold, SP1, SP2)

  • CISA KEV

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-03-10 Known ransomware campaign use: Unknown

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.