s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2009-1537 high

📛 Threat Title

Microsoft DirectX: Microsoft DirectX NULL Byte Overwrite Vulnerability

Category: exploited-vulnerability Published: Source updated: First seen: Last updated: Source: CISA KEV CVEs

Description

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. Added to KEV: 2026-05-20. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-06-03.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain quartz.dll

IOC database

Type
domain
Value
quartz.dll
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat CVE-2009-1537

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

cve CVE-2009-1537

IOC database

Type
cve
Value
CVE-2009-1537
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Microsoft DirectX NULL Byte Overwrite Vulnerability

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (15)

Remediations (9)

  • web:www.scyscan.com

    Description Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

  • web:dailycve.com

    Impact Remote code execution with user privileges. Full system compromise - install programs, view/change/delete data, create new accounts. Wormable via drive-by download or email attachments. Affects Windows Media Player, Internet Explorer, and any DirectShow-based media player. Exploited in targeted attacks during May 2009 prior to patch .

  • web:msrc.microsoft.com

    Security Update Guide - Microsoft Security Response Center

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:www.bleepingcomputer.com

    Today is Microsoft's February 2025 Patch Tuesday, which includes security updates for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks.

  • web:cybersixt.com

    CISA has added CVE‑2009‑1537 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Microsoft DirectX, specifically the QuickTime Movie Parser Filter in quartz.dll, and is named the Microsoft DirectX NULL Byte Overwrite Vulnerability. It allows remote attackers to execute arbitrary code by supplying a specially crafted QuickTime media file.

  • web:www.computerworld.com

    Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...

  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

  • CISA KEV (via KEVin)

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-06-03

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.