ZeroHour

CVE-2009-1537

KEVmass

Null Byte Overwrite RCE in Microsoft DirectX QuickTime Parser (quartz.dll)

CISA: Microsoft DirectX NULL Byte Overwrite Vulnerability

CVSS
EPSS
51%p99
Published
KEV added
AI analysis

CVE-2009-1537 is a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter inside quartz.dll, a DirectShow component of Microsoft DirectX. It is triggered when the affected DirectShow component parses a crafted QuickTime (.mov) media file, such as one opened from a website, media player, or email. A successful exploit allows a remote attacker to execute arbitrary code on the targeted system. Any Microsoft installation with the vulnerable DirectX/DirectShow component is affected, with real-world risk concentrated on systems that render untrusted QuickTime media. The flaw is long-standing (2009) but CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-20, confirming active exploitation; EPSS puts its 30-day exploitation probability at 51.2% (99th percentile), while no public PoC is known and ransomware use is unconfirmed.

What to do: Apply Microsoft's mitigations per vendor instructions, and follow BOD 22-01 requirements for cloud services in federal environments; ensure affected systems have the vendor's updated quartz.dll/DirectShow fix installed rather than relying on default installations. Until patched, avoid opening untrusted QuickTime (.mov) files and block or inspect .mov files delivered via email and web downloads. Treat this as a high priority given the KEV listing and elevated EPSS score, even though ransomware association is not yet confirmed.

Affected
Microsoft DirectX
Estimated exposure
masshundreds of millions of Windows installations (DirectX/DirectShow ships as a standard Windows component) — quartz.dll/DirectShow is present on essentially all Windows systems, so exposure follows the global Windows install base, though actual exploit risk is limited to machines that open attacker-supplied QuickTime media files.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

CISA Known Exploited Vulnerability
Affected
Microsoft DirectX
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
DirectX

In the news