CVE detail
CVE-2008-0015 — Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Published 2026-02-17 · Modified 2026-02-17 · Source kev
HIGH
severity
CVSS-derived band
0.7673
EPSS probability
exploitation probability, 30d
99.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2026-03-10
⚠ Actively exploited in the wild — CISA KEV listed 2026-02-17, federal remediation due 2026-03-10.
Description
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References