CVE-2008-0015 – Microsoft Windows Video ActiveX Control Vulnerability

The CISA added CVE-2008-0015 to the Known Exploited Vulnerability Database on 17 February 2026.

Despite being originally disclosed in 2009, this CVE was freshly added to CISA’s KEV catalog in February 2026, meaning threat actors are actively leveraging it — likely against unpatched or legacy Windows systems still running older versions. The vulnerability must be patched on legacy systems by March 10, 2026.

About the CVE-2008-0015 Vulnerability

  • It was first disclosed on 9 July 2009.
  • It carries a CVSS score of 9.3 with HIGH severity.
  • An attacker can achieve remote code execution by setting up a specially crafted web page. The attack requires the victim to visit a malicious web page — making it a drive-by/browser-based attack.
  • It was actively exploited in the wild in July 2009. It has been recently re-added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on February 17, 2026 CISA, indicating continued or renewed active exploitation.
  • The vulnerability is based on a weakness CWE-119 – Improper Restriction of Operations within the Bounds of a Memory Buffer.
  • Federal agencies are advised to secure the systems by installing the security update by March 10, 2026. If patch cannot be installed, it is recommended to stop using these legacy systems after the due date.

What Windows versions are affected by CVE-2008-0015?

The following Microsoft platforms are affected by CVE-2008-0015:

  • Microsoft Windows 2000 SP4
  • Windows XP SP2 and SP3
  • Windows Server 2003 SP2
  • Windows Vista (Gold, SP1, SP2)
  • Windows Server 2008 (Gold and SP2).

Remediation of CVE-2008-0015

Microsoft released a security update to address CVE-2008-0015 via MS09-032 and later addressed in MS09-037.

CISA advises to apply mitigations per vendor instructions, and follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you are unable to install the patch, disabling the affected ActiveX control (kill-bit) is an interim workaround.

Reference links: