Skip to content
COOEY

EXPOSURES › CVE-2009-1537

CVE-2009-1537

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-05-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2009-1537 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildransomwareunpatched

Microsoft DirectX contained a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter allowing remote code execution via crafted media files.

This 2009 vulnerability was actively exploited in the wild and linked to ransomware campaigns, exposing defense contractors to remote code execution through unpatched DirectX components. DIB organizations must verify patch levels on legacy systems and prioritize updates to prevent exploitation of this known, high-severity flaw.

Shame score — The vulnerability was actively exploited in the wild for years before being patched, indicating a significant lapse in vendor response and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized