CVE-2008-0015Active Exploitation(microsoft / windows_2003_server)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch microsoft windows_2003_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-10. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_2003_server
  • windows_xp

Threat summary

  • Active exploitation appears in 18 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 22 mentions across 6 observed days

What's happening

  • Active exploitation reported across 18 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 14 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 11 mentions (2026-02-18); latest day: 1
  • 22 total mentions across 6 days

Affected systems

Vendors
Products
windows_2003_serverwindows_xp

1 version affected across 2 products

Deep dive

Activity timeline22 mentions / 6d
036811Mentions · 2026-02-17: 2Mentions · 2026-02-18: 11Mentions · 2026-02-19: 2Mentions · 2026-02-20: 3Mentions · 2026-04-30: 3Mentions · 2026-07-03: 1PoC Mentioned / Linked · 2026-02-18: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-18: 10Active Exploitation · 2026-02-19: 2Active Exploitation · 2026-02-20: 3Active Exploitation · 2026-04-30: 2Patch / Workaround · 2026-02-18: 3Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-07-03: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 10Technical Details · 2026-02-20: 2Technical Details · 2026-07-03: 102-1702-1802-1902-2004-3007-03
Signal classification4 categories
Active Exploitation
1881.8%
Patch
29.1%
Disclosure
14.5%
General
14.5%
Referenced assets21 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-172
Active Exploitation1Disclosure1
2026-02-1811
Active Exploitation10Patch1
2026-02-192
Active Exploitation2
2026-02-203
Active Exploitation3
2026-04-303
Active Exploitation2General1
2026-07-031
Patch1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 4 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2020-7796: Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability CVE-2024-7694: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability CVE-2026-2441: Google Chromium CSS Use-After-Free Vulnerability

    Post summary

    CISA announced four CVEs added to the KEV catalog, detailing each vulnerability type but without providing exploits, patches, or evidence of active exploitation.

    1702484.0K
    162.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/17追加) 🛡️No.1520 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:サーバサイドのリクエストフォージェリ (CWE-918 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、WebEx zimlet がインストールされ、zimlet JSP が有効になっている場合、リモートからSSRFの脆弱性の影響を受ける恐れがあります。 https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7 🛡️No.1521 CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability ============= CVSSスコア: 7.2 (Base) / TWCERT/CC CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 種別:危険なタイプのファイルの無制限アップロード (CWE-434/ TWCERT/CC) 深刻度:重要 ---------------------- 悪用時影響: 製品プラットフォームの管理者権限を持つ攻撃者により、リモートから悪意のあるファイルをアップロードし、サーバー上で任意のシステムコマンドを実行される恐れがあります。 https://teamt5.org/en/posts/vulnerability-notice-threat-sonar-anti-ransomware-20240715/ https://www.twcert.org.tw/en/cp-139-8000-e5a5c-2.html 🛡️No.1522 CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:スタックベースのバッファオーバーフロー (CWE-121/ CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWeb ページを介して、閲覧したユーザーの権限でコード実行される恐れがあります。 https://web.archive.org/web/20110305211119/https://www.microsoft.com/technet/security/bulletin/ms09-032.mspx 🛡️No.1523 CVE-2026-2441 Google Chromium CSS Use-After-Free Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416/ CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたHTML ページを介して、ヒープ破壊を行う恐れがあります。この脆弱性は、Google Chrome、Microsoft Edge、Opera など、Chromium を利用する複数のウェブブラウザに影響を与える可能性があります。 https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html CISA Adds Four Known Exploited Vulnerabilities to Catalog https://www.cisa.gov/news-events/alerts/2026/02/17/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed active exploitation of four CVEs and added them to its catalog of known exploited vulnerabilities. The post provides technical details but no PoC, exploit code, patch, or false‑positive information.

    010814.3K
    42.5K followersView on X
  • DC3 DCISE@DC3DCISE
    Patch

    🚨 CISA adds 4 flaws to the KEV. Prioritize patching: 🌐 Chrome: CVE-2026-2441 (UAF, RCE) 🛡️ TeamT5 ThreatSonar: CVE-2024-7694 (File Upload) 📧 Zimbra: CVE-2020-7796 (SSRF) 💻 Windows: CVE-2008-0015 (ActiveX RCE) #Patching #KEV #VulnerabilityManagement #InfoSec #DCISEWarning

    Post summary

    CISA announces four new flaws added to the KEV and urges immediate patching of Chrome, TeamT5 ThreatSonar, Zimbra, and Windows.

    01011501
    729 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    CISA adds 4 flaws to KEV: Ancient Windows ActiveX bug (CVE-2008-0015) & new Chrome zero-day (CVE-2026-2441). Patch now to prevent exploitation. #CISA #KEV #CyberSecurity #InfoSec #WindowsXP #Chrome #ZeroDay https://securityonline.info/cisa-adds-2008-windows-flaw-chrome-zero-day-to-kev/

    Post summary

    CISA has added CVE‑2008‑0015 and CVE‑2026‑2441 to its KEV list and urges users to apply the available patches to prevent exploitation.

    11001278
    10.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2008-0015 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-17, establishing a remediation due date of 2026-03-10 for impacted fede

    Post summary

    CISA has identified CVE-2008-0015 as a known exploited vulnerability, setting a remediation due date, which signals active exploitation in the wild.

    1000016
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2008-0015. What happened CISA added CVE-2008-0015 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-17, establishing a remediation due date of 2026-03-10 for impacted federal enterprises CISA KEV catalog.

    Post summary

    CVE‑2008‑0015 has been listed in the CISA KEV catalog, confirming that it is actively being exploited and prompting a scheduled remediation deadline for federal agencies, but no PoC, exploit code, or detailed technical information is disclosed.

    1000020
    152 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    A decade-old Windows vulnerability, CVE-2008-0015, is actively exploited. Ensure your systems are patched and up-to-date to prevent potential breaches. Link: https://thedailytechfeed.com/decade-old-windows-vulnerability-cve-2008-0015-actively-exploited-urgent-patch-required/ #Security #Windows #Vulnerability #Patch #Exploit #Cyber #Protection #Update #Breach #Threat #Software #Technology #Alert #Defense #Safety #Risk #Hack #System #Network #IT

    Post summary

    CVE-2008-0015, a decade-old Windows vulnerability, is reportedly being actively exploited in the wild; systems should be patched promptly to mitigate risk.

    01000114
    220 followersView on X
  • ProbablyPwned@probablypwned
    Active Exploitation

    CISA confirms active exploitation of Chrome CVE-2026-2441, Zimbra SSRF, Windows ActiveX CVE-2008-0015, and ThreatSonar flaws. Federal agencies have until March 10 to patch. Read more: https://www.probablypwned.com/article/cisa-kev-chrome-zimbra-activex-threatsonar-february-2026

    Post summary

    CISA confirms that Chrome CVE‑2026‑2441, Zimbra SSRF, Windows ActiveX CVE‑2008‑0015, and ThreatSonar flaws are being actively exploited, and federal agencies must patch by March 10.

    1000059
    12 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/17/cisa-adds-four-known-exploited-vulnerabilities-catalog CVE-2008-0015 Microsoft Windows ビデオ ActiveX コントロールのリモート コード実行の脆弱性 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) のサーバー側リクエストフォージェリ脆弱性

    Post summary

    CISA announced that four known exploited vulnerabilities, including CVE‑2008‑0015 (RCE) and CVE‑2020‑7796 (SSRF), are active in the wild, underscoring the need for timely remediation.

    1000062
    44 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが4つの既知の脆弱性をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 17) CVE-2008-0015 Microsoft Windows ビデオ ActiveX コントロールのリモート コード実行の脆弱性 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) のサーバー側リクエストフォージェリ脆弱性 CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware の危険な種類のファイルの無制限アップロードの脆弱性 CVE-2026-2441 Google Chromium CSS の解放後使用の脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/17/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that four CVEs are known to be exploited in the wild, listing each vulnerability’s key technical characteristics without mentioning patches or PoCs.

    00010245
    4.7K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/active-exploit-cve-2008-0015-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely links to a page about CVE‑2008‑0015 with no further information provided.

    0000022
    152 followersView on X
  • twelvesec@twelvesec
    Active Exploitation

    #CISA added four #security flaws (CVE-2026-2441, CVE-2024-7694, CVE-2020-7796, CVE-2008-0015) to its KEV catalogue, citing evidence of active exploitation in the wild. #CyberSecurity #InfoSec https://ift.tt/rAiQ0MN https://t.co/W1h3dmwdH7

    Post summary

    CISA has added four CVEs to its KEV catalog, citing evidence that these vulnerabilities are being actively exploited in the wild.

    0000083
    1.5K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update - CVE-2026-2441 (CVSS score: 8.8) - A use-after-free vulnerability in Google Chrome - CVE-2024-7694 (CVSS score: 7.2) - An arbitrary file upload vulnerability in TeamT5 ThreatSonar - CVE-2020-7796 (CVSS score: 9.8) - A server-side request forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite - CVE-2008-0015 (CVSS score: 8.8) - A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control https://nuel.ink/MhJU0b

    Post summary

    CISA reports four CVEs—one in Google Chrome, one in TeamT5 ThreatSonar, one in Synacor Zimbra, and one in Microsoft Windows—under active exploitation, with brief technical details but no PoC, exploit code, or patch references.

    0000082
    1.1K followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Adds Actively Exploited Chrome, Zimbra, Windows ActiveX, and ThreatSonar Flaws to KEV CISA updated its Known Exploited Vulnerabilities (KEV) catalog with four issues—Chrome UAF (CVE-2026-2441), Zimbra SSRF (CVE-2008-0015), Windows Video ActiveX Control (CVE-2020-7796), and TeamT5 ThreatSonar (CVE-2024-7694)—noting confirmed exploitation for at least Chrome and broad scanning/exploitation activity for the Windows flaw. This matters because KEV inclusion is a high-confidence “patch-now” signal and these bugs can enable RCE/credentialed footholds leading to malware delivery (e.g., Dogkild worm) and deeper compromise. 🕷️ Malware: Dogkild worm (mentioned) 🎯 Target: Global/Enterprise + Government #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/updated-cisa-vulnerabilities-catalog-adds-chrome-zimbra-windows-threatsonar-flaws

    Post summary

    CISA’s KEV update confirms that Chrome UAF, Zimbra SSRF, Windows ActiveX and ThreatSonar vulnerabilities are actively exploited, signaling urgent patching and remediation efforts.

    00000109
    174 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    CISA adds long-standing Windows flaw CVE-2008-0015 to KEV after confirming active exploitation. Bug in Windows Video ActiveX Control enables remote code execution. Patch or mitigate promptly. #Windows https://threatcluster.io/cluster/cisa-adds-cve-2008-0015-to-kev-catalog-due-to-active-exploit-fb61e72f

    Post summary

    CISA has added CVE‑2008‑0015 to the KEV catalog after confirming it is actively exploited in the wild, and recommends immediate patching or mitigation.

    0000029
    71 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags Actively Exploited Windows ActiveX RCE (CVE-2008-0015) and Sets March 10 Deadline CISA added CVE-2008-0015 (Microsoft Windows Video ActiveX Control RCE) to the KEV catalog after confirmed in-the-wild exploitation, where attackers lure victims to malicious web pages that trigger the vulnerable control in legacy IE/ActiveX contexts to run code with the logged-in user’s privileges. This matters because KEV inclusion signals real exploitation risk and forces urgent mitigation—especially for organizations still running legacy Windows/IE modes or environments where ActiveX remains enabled. 🎯 Target: USA/Government (FCEB) + Global/Enterprise (Legacy Windows/IE) #️⃣ Category: #Vulnerability #BlueTeam #CyberLaw 🔗 URL: https://cyberpress.org/cisa-adds-actively-exploited-windows-activex-rce-flaw-to-kev-catalog/

    Post summary

    CISA has confirmed that CVE‑2008‑0015 is actively exploited in the wild, prompting urgent mitigation for legacy Windows/IE environments.

    0000025
    176 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags 2008-Era Windows ActiveX RCE as Actively Exploited (CVE-2008-0015) CISA added CVE-2008-0015 (Windows Video ActiveX Control) to the KEV catalog after evidence of in-the-wild exploitation via malicious web pages that load the vulnerable ActiveX control in Internet Explorer, enabling arbitrary code execution under the logged-on user context. This matters because legacy/unpatched Windows estates and IE/ActiveX remnants remain a viable intrusion path—CISA set a March 10, 2026 remediation deadline for U.S. federal agencies, and enterprises should treat it as an urgent legacy-risk closure item. 🎯 Target: USA/Government (FCEB) + Global/Windows (Legacy/IE) #️⃣ Category: #Vulnerability #BlueTeam #CyberLaw 🔗 URL: https://cybersecuritynews.com/windows-video-activex-control-rce-flaw-exploited/

    Post summary

    CISA confirms that CVE‑2008‑0015, a Windows ActiveX Remote Code Execution flaw, is being actively exploited through malicious web pages, urging urgent remediation of legacy systems.

    0000026
    176 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags 4 Actively Exploited Bugs: Chrome CSS Zero-Day, Windows ActiveX RCE, Zimbra SSRF, ThreatSonar Upload Flaw CISA added four vulnerabilities to its KEV catalog—CVE-2026-2441 (Chrome/Chromium CSS UAF, exploited in the wild), CVE-2008-0015 (Windows Video ActiveX/DirectShow RCE), CVE-2020-7796 (Zimbra ZCS SSRF), and CVE-2024-7694 (TeamT5 ThreatSonar arbitrary file upload that can enable server-side command execution)—and ordered U.S. federal agencies to remediate by March 10, 2026. This matters because KEV inclusion indicates real-world exploitation risk and sets an urgent patch/mitigation clock for both public and private-sector defenders running affected stacks. 🎯 Target: USA/Government (FCEB) + Global/Enterprise #️⃣ Category: #Vulnerability #BlueTeam #CyberLaw 🔗 URL: https://securityaffairs.com/188163/uncategorized/u-s-cisa-adds-google-chromium-css-microsoft-windows-teamt5-threatsonar-anti-ransomware-and-zimbra-flaws-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA has added four CVEs to its KEV catalog, confirming they are actively exploited in the wild and urging federal agencies to remediate by March 10, 2026.

    0000061
    176 followersView on X
  • Israel@f1tym1
    Active Exploitation

    CISA Adds Windows Video ActiveX Control RCE Flaw to KEV Catalog Following Active Exploitation https://ift.tt/6jmCDnu A long-dormant Microsoft Windows vulnerability, CVE-2008-0015, has been added to the Known Exploited Vulnerabilities (KEV) catalog following evidence of active…

    Post summary

    CISA has added CVE‑2008‑0015 to its KEV catalog after confirming it is actively exploited in the wild.

    0000036
    922 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags 4 Actively Exploited Bugs (Chrome, Zimbra, Windows ActiveX, ThreatSonar) — Patch Now CISA added four vulnerabilities to the KEV catalog: Chrome UAF CVE-2026-2441, TeamT5 ThreatSonar file-upload RCE CVE-2024-7694, Zimbra SSRF CVE-2020-7796, and Windows Video ActiveX RCE CVE-2008-0015, indicating in-the-wild exploitation and requiring rapid remediation (FCEB deadline: March 10, 2026). This update matters because it spans browser, email, endpoint, and security tooling—raising compromise likelihood for orgs that lag on patching and increasing urgency for detection/hunting around exploit attempts. 🎯 Target: Global/All Sectors #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://thehackernews.com/2026/02/cisa-flags-four-security-flaws-under.html

    Post summary

    CISA has identified four CVEs that are actively exploited in the wild and urges rapid patching by March 10, 2026.

    0000079
    176 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_2003_server---
OSmicrosoftwindows_2003_server---
OSmicrosoftwindows_2003_server---
OSmicrosoftwindows_xp---
OSmicrosoftwindows_xp---

Explore more