PT-2009-1181 · Microsoft · Windows+1

·

CVE-2008-0015

·

Published

2009-07-07

·

Updated

2026-07-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 SP4 Microsoft Windows XP SP2 and SP3 Microsoft Windows Server 2003 SP2 Microsoft Windows Vista Gold, SP1, and SP2 Microsoft Windows Server 2008 Gold and SP2
Description A stack-based buffer overflow exists in the CComVariant::ReadFromStream() function within the Active Template Library (ATL), specifically affecting the MPEG2TuneRequest ActiveX control located in msvidctl.dll in DirectShow. A remote attacker can execute arbitrary code with the privileges of the logged-on user by inducing a user to view a specially crafted web page. This issue was exploited in the wild in July 2009.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0015

Affected Products

Video Activex Control
Windows