CVE-2008-0015
9.5 CISA KEVMicrosoft · Windows
A stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library allows unauthenticated remote attackers to execute arbitrary code via a crafted web page.
Executive summary
This critical stack-based buffer overflow vulnerability in Microsoft Windows ActiveX controls is confirmed to be actively exploited in the wild and poses a severe risk of remote code execution.
Vulnerability
The flaw exists in the CComVariant::ReadFromStream function within the Active Template Library, specifically impacting the MPEG2TuneRequest ActiveX control in msvidctl.dll. An unauthenticated attacker can trigger this stack-based buffer overflow by enticing a user to view a specially crafted web page.
Business impact
Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged-in user. Given the CVSS score of 9.5, this vulnerability represents a critical threat that could lead to full system compromise, data exfiltration, or the deployment of persistent malware within the environment.
Remediation
Immediate Action: Apply the security update provided in Microsoft Security Bulletin MS09-032 (KB973346) immediately to all affected systems.
Proactive Monitoring: Review system logs for unexpected execution of msvidctl.dll or suspicious outbound network traffic originating from browser processes that may indicate an exploit attempt.
Compensating Controls: Disable the vulnerable ActiveX control via registry keys if immediate patching is not feasible, or utilize Group Policy to restrict the execution of ActiveX controls in Internet Explorer.
Exploitation status
Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.
Analyst recommendation
Due to the confirmed active exploitation and the critical nature of the remote code execution risk, this vulnerability must be treated as a high priority for remediation. Organizations should verify that the MS09-032 (KB973346) update has been successfully applied across all supported and legacy Windows environments to eliminate this exposure.
More Microsoft CVEs
Sources
- 35558 Vulnerability database entry
- TA09-223A Third-party advisory
- blogs.technet.com
- 55651 Vulnerability database entry
- oval:org.mitre.oval:def:6333 Vulnerability database entry
- 35585 Vulnerability database entry
- 36187 Third-party advisory
- MS09-032 Vendor advisory