SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2009-1537

Microsoft DirectX NULL Byte Overwrite Vulnerability

KEVHIGH 8.8EPSS 51.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 June 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
51.21% probability · 99th percentile
CISA KEV
Listed 20 May 2026 · due 3 June 2026
Weakness
CWE-158
Affected
microsoft/directx · microsoft/windows 2000 · microsoft/windows 2003 server · microsoft/windows server 2003 · microsoft/windows xp
Source
secure@microsoft.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 ; https://nvd.nist.gov/vuln/detail/CVE-2009-1537

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.