CVE-2008-0015 describes a stack-based buffer overflow in the CComVariant::ReadFromStream function within the Active Template Library (ATL), specifically impacting the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow across various Microsoft Windows versions, including XP and Server 2003. This vulnerability carries a high CVSS score of 8.8, indicating it can be exploited remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with Metasploit modules and ExploitDB entries confirming exploit code availability, and has garnered significant community discussion and media coverage, including being added to CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:-:sp2:itanium:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:-:sp2:x64:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.