Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-0015

97
FAUCET Score

CVE-2008-0015 describes a stack-based buffer overflow in the CComVariant::ReadFromStream function within the Active Template Library (ATL), specifically impacting the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow across various Microsoft Windows versions, including XP and Server 2003. This vulnerability carries a high CVSS score of 8.8, indicating it can be exploited remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with Metasploit modules and ExploitDB entries confirming exploit code availability, and has garnered significant community discussion and media coverage, including being added to CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2003_server:-:sp2:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2003_server:-:sp2:itanium:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_2003_server:-:sp2:x64:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
76.73%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Feb 17, 2026
Metasploit: Microsoft DirectShow (msvidctl.dll) MPEG-2 Memory Corruption · Jul 5, 2009
ExploitDB: EDB-16615 · Apr 30, 2010
This CVE's current EPSS score of 0.7673 is in the 100th percentile among its peer group of 14,825 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Patches (1)

microsoftvendor investigatingvia nvd_reference
View patch

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blogs.technet.com / srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx
Broken Link
isc.sans.org / diary.html
Exploit
osvdb.org / 55651
Broken Link
docs.microsoft.com / en-us/security-updates/securitybulletins/2009/ms09-032
Third Party Advisory
docs.microsoft.com / en-us/security-updates/securitybulletins/2009/ms09-037
Third Party Advisory
secunia.com / advisories/36187
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6333
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6363
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7436
Broken Link
csis.dk / dk/nyheder/nyheder.asp
Exploit
iss.net / threats/329.html
Exploit
kb.cert.org / vuls/id/180513
US Government Resource
microsoft.com / technet/security/advisory/972890.mspx
Vendor Advisory
securityfocus.com / bid/35558
Broken Link
securityfocus.com / bid/35585
Broken Link
securitytracker.com / id
Broken Link
us-cert.gov / cas/techalerts/TA09-187A.html
US Government Resource
us-cert.gov / cas/techalerts/TA09-195A.html
US Government Resource
us-cert.gov / cas/techalerts/TA09-223A.html
US Government Resource
vupen.com / english/advisories/2009/2232
Broken Link