LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 17, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2008-0015 to its Known Exploited Vulnerabilities catalog on Feb 17, 2026, with a federal patch deadline of Mar 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the…

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker can exploit it by serving a specially crafted web page; when the page is rendered in a vulnerable environment, the flaw allows arbitrary code to run with the privileges of the logged-on user. The issue affects Microsoft Windows systems that expose the Video ActiveX Control to untrusted web content, making it a vector for remote compromise without user interaction beyond viewing the page.

How it works

The vulnerability resides in the Microsoft Windows Video ActiveX Control. An attacker constructs a malicious web page that triggers the control when loaded by a browser or application that hosts ActiveX components. Successful exploitation grants code execution at the same privilege level as the current user.

Am I affected? How to find it in your systems

Inventory all Windows endpoints and servers that render web content through browsers or legacy applications capable of instantiating ActiveX controls. Focus on systems that have not received the vendor update addressing this control. Check installed components for the Video ActiveX Control and review browser configurations that permit ActiveX execution from untrusted zones. Review proxy or web-filter logs for unexpected outbound connections or script execution originating from user workstations after visits to unknown domains. Confirm exact affected configurations and versions against the vendor advisory.

How to remediate

Apply mitigations per the vendor instructions referenced in the advisory. Where the update is available, deploy it through standard patch-management channels and verify installation on all managed systems. After patching, audit Group Policy or browser settings to restrict ActiveX controls to trusted zones only and disable the control where it is not required for business functions.

If you can't patch immediately

Follow the vendor mitigation steps or, if those are unavailable, discontinue use of the affected product. For cloud-hosted services, apply any applicable BOD 22-01 guidance. Segment networks so that systems still running the vulnerable control cannot reach untrusted external sites. Monitor endpoint and web-proxy logs for indicators of the control being invoked from unexpected sources, and consider virtual patching or content-filtering rules that block pages attempting to load the Video ActiveX Control from untrusted origins.

If your data may have been exposed

Actively exploited remote-code-execution flaws of this type have led to unauthorized access and data exposure. Organizations can run a free exposure scan of their email domains to check for presence in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVFeb 17, 2026
Federal patch deadlineMar 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities