CVE-2008-0015
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
8.8
CVSS 3.1
76.6 %
EPSS (current)
2026-02-17
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / Windows
Published: 2009-07-07 · Due (CISA): 2026-03-10
CWE: CWE-119 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| metasploit | exploit/windows/browser/msvidctl_mpeg2 | exploit/windows/browser/msvidctl_mpeg2 | 2009-07-05 |
| exploitdb | 9108 | Microsoft Internet Explorer 7 Video - ActiveX Remote Buffer Overflow | 2009-07-10 |
| exploitdb | 16615 | Microsoft DirectShow - 'msvidctl.dll' MPEG-2 Memory Corruption (MS09-032/MS09-037) (Metasploit) | 2010-04-30 |
References only — no downloads or instructions.