CVE-2008-0015

9.5 CISA KEV

Microsoft · Windows

A stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library allows unauthenticated remote attackers to execute arbitrary code via a crafted web page.

Executive summary

This critical stack-based buffer overflow vulnerability in Microsoft Windows ActiveX controls is confirmed to be actively exploited in the wild and poses a severe risk of remote code execution.

Vulnerability

The flaw exists in the CComVariant::ReadFromStream function within the Active Template Library, specifically impacting the MPEG2TuneRequest ActiveX control in msvidctl.dll. An unauthenticated attacker can trigger this stack-based buffer overflow by enticing a user to view a specially crafted web page.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged-in user. Given the CVSS score of 9.5, this vulnerability represents a critical threat that could lead to full system compromise, data exfiltration, or the deployment of persistent malware within the environment.

Remediation

Immediate Action: Apply the security update provided in Microsoft Security Bulletin MS09-032 (KB973346) immediately to all affected systems.

Proactive Monitoring: Review system logs for unexpected execution of msvidctl.dll or suspicious outbound network traffic originating from browser processes that may indicate an exploit attempt.

Compensating Controls: Disable the vulnerable ActiveX control via registry keys if immediate patching is not feasible, or utilize Group Policy to restrict the execution of ActiveX controls in Internet Explorer.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.

Analyst recommendation

Due to the confirmed active exploitation and the critical nature of the remote code execution risk, this vulnerability must be treated as a high priority for remediation. Organizations should verify that the MS09-032 (KB973346) update has been successfully applied across all supported and legacy Windows environments to eliminate this exposure.

More Microsoft CVEs

Sources