CVE-2009-1537
Summary
| CVE | CVE-2009-1537 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-29 18:30:00 UTC |
| Updated | 2026-05-21 12:57:12 UTC |
| Description | Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability." |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.530160000 probability, percentile 0.980080000 (date 2026-06-02)
CISA KEV: Listed on 2026-05-20; due 2026-06-03; ransomware use Unknown
Problem Types: NVD-CWE-noinfo | CWE-158 | n/a | CWE-158 CWE-158 Improper Neutralization of Null Byte or NUL Character
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | DirectX |
| Name | Microsoft DirectX NULL Byte Overwrite Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Directx | 7.0 | All | All | All |
| Application | Microsoft | Directx | 7.0a | All | All | All |
| Application | Microsoft | Directx | 7.1 | All | All | All |
| Application | Microsoft | Directx | 8.1 | All | All | All |
| Application | Microsoft | Directx | 8.1b | All | All | All |
| Application | Microsoft | Directx | 9.0 | All | All | All |
| Application | Microsoft | Directx | 9.0a | All | All | All |
| Application | Microsoft | Directx | 9.0b | All | All | All |
| Application | Microsoft | Directx | 9.0c | All | All | All |
| Operating System | Microsoft | Windows 2000 | All | sp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Microsoft DirectShow QuickTime Parsing Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Microsoft DirectX DirectShow QuickTime Video Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link |
| osvdb.org/54797 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Your request has been blocked. This could be due to several reasons. | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Microsoft DirectShow vulnerability | af854a3a-2127-422b-91ae-364da2661108 | isc.sans.org | Not Applicable |
| The Microsoft Security Response Center (MSRC) : Microsoft Security Advisory 971778 Vulnerability in Microsoft DirectShow Released | af854a3a-2127-422b-91ae-364da2661108 | blogs.technet.com | Vendor Advisory |
| SecurityTracker.com Archives - Microsoft DirectX Bug in DirectShow QuickTime Parser Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Security Research & Defense : New vulnerability in quartz.dll Quicktime parsing | af854a3a-2127-422b-91ae-364da2661108 | blogs.technet.com | Vendor Advisory |
| Microsoft Security Bulletin MS09-028 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA09-195A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-05-20T00:00:00.000Z | CVE-2009-1537 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.