CVE-2009-1537
high
📛 Threat Title
Microsoft DirectX: Microsoft DirectX NULL Byte Overwrite Vulnerability
Description
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. Added to KEV: 2026-05-20. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-06-03.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
quartz.dll
IOC database
- Type
- domain
- Value
quartz.dll- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat CVE-2009-1537
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
cve
CVE-2009-1537
IOC database
- Type
- cve
- Value
CVE-2009-1537- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Microsoft DirectX NULL Byte Overwrite Vulnerability
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (15)
- Vendor Advisory CISA KEV CVEs
- NVD reference CISA KEV CVEs
- NVD reference CISA KEV CVEs
- NVD reference CISA KEV CVEs
- NVD reference CISA KEV CVEs
- Vendor Advisory CISA KEV CVEs
- CISA notes reference CISA KEV CVEs
-
NVD detail: CVE-2009-1537
CISA KEV CVEs
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
- NVD reference CISA KEV CVEs
- Patch, Vendor Advisory CISA KEV CVEs
- NVD reference CISA KEV CVEs
- NVD reference CISA KEV CVEs
- US Government Resource CISA KEV CVEs
- Vendor Advisory CISA KEV CVEs
- Vendor Advisory CISA KEV CVEs
Remediations (9)
-
web:www.scyscan.com
Description Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
-
web:dailycve.com
Impact Remote code execution with user privileges. Full system compromise - install programs, view/change/delete data, create new accounts. Wormable via drive-by download or email attachments. Affects Windows Media Player, Internet Explorer, and any DirectShow-based media player. Exploited in targeted attacks during May 2009 prior to patch .
-
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:www.bleepingcomputer.com
Today is Microsoft's February 2025 Patch Tuesday, which includes security updates for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks.
-
web:cybersixt.com
CISA has added CVE‑2009‑1537 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Microsoft DirectX, specifically the QuickTime Movie Parser Filter in quartz.dll, and is named the Microsoft DirectX NULL Byte Overwrite Vulnerability. It allows remote attackers to execute arbitrary code by supplying a specially crafted QuickTime media file.
-
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
CISA KEV (via KEVin)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-06-03
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.