ZeroHour

CVE-2008-0015

KEVmass

Remote Code Execution in Microsoft Windows Video ActiveX Control

CISA: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

CVSS
EPSS
77%p100
Published
KEV added
AI analysis

CVE-2008-0015 is a remote code execution vulnerability in the Microsoft Windows Video ActiveX Control, a browser-hostable component bundled with Windows. It is triggered when a user views a specially crafted web page that instantiates the vulnerable control, which lets the attacker's code run in the context of the logged-on user. A successful attacker gains the same user rights as the victim, so an administrator browsing with elevated rights would face full system compromise; any Windows user who views web content with the control enabled is affected. Per CISA the flaw is being actively exploited (added to the Known Exploited Vulnerabilities catalog on 2026-02-17, ransomware use unknown), and EPSS assigns it a 76.7% probability of exploitation within 30 days, placing it in the top percentile.

What to do: Apply Microsoft's security update for the Windows Video ActiveX Control; as interim mitigation, apply the vendor-documented kill-bit registry keys (including the out-of-band 'Isolated' kill bit Microsoft shipped) so the control cannot be instantiated in Internet Explorer. Because the flaw is on the CISA KEV list, federal agencies must remediate within BOD 22-01 timelines (or apply vendor mitigations for cloud services), and defenders should audit legacy Windows hosts for use of this control, discourage browsing with administrator rights, and prioritize patching systems used for web browsing.

Affected
Microsoft WindowsMicrosoft Windows per CISA; specific affected Windows version ranges were not enumerated in the provided data
Estimated exposure
massmass-scale: the vulnerable ActiveX control shipped by default across the Windows installed base (on the order of hundreds of millions of endpoints… — The control was bundled with widely deployed Windows client and server editions, so at disclosure exposure approximated the entire Windows base (Windows runs on well over a billion devices), and today only unpatched legacy systems remain…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows

In the news