Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
Published May 29, 2009 ·Due Jun 3, 2026
8.8
HIGHCVSS 3.1
EPSS 51.21%
Description
Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
Affected products
No data.
Configuration 1
- 7.0
- 7.0a
- 7.1
- 8.1
- 8.1b
- 9.0
- 9.0a
- 9.0b
- 9.0c
- n/a
Configuration 2
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
May 20, 2026
Patch Due
Jun 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 20, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (34 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 51.21% (0.51207) | 98.91th | v5 (v2026.06.15) |
| Jun 15, 2026 | 50.93% (0.50926) | 98.78th | v5 (v2026.06.15) |
| May 25, 2026 | 53.02% (0.53016) | 98.00th | v4 (v2025.03.14) |
| May 22, 2026 | 55.49% (0.55490) | 98.11th | v4 (v2025.03.14) |
| May 21, 2026 | 74.07% (0.74066) | 98.86th | v4 (v2025.03.14) |
| Dec 28, 2025 | 68.08% (0.68076) | 98.53th | v4 (v2025.03.14) |
| Dec 27, 2025 | 65.02% (0.65019) | 98.41th | v4 (v2025.03.14) |
| Oct 28, 2025 | 68.80% (0.68797) | 98.55th | v4 (v2025.03.14) |
| Oct 27, 2025 | 65.80% (0.65797) | 98.44th | v4 (v2025.03.14) |
| Oct 1, 2025 | 68.80% (0.68797) | 98.58th | v4 (v2025.03.14) |
| Mar 30, 2025 | 65.80% (0.65797) | 98.37th | v4 (v2025.03.14) |
| Mar 29, 2025 | 68.96% (0.68959) | 98.12th | v4 (v2025.03.14) |
| Mar 17, 2025 | 65.80% (0.65797) | 98.36th | v4 (v2025.03.14) |
| Jan 12, 2025 | 92.49% (0.92494) | 99.23th | v3 (v2023.03.01) |
| Dec 17, 2024 | 87.25% (0.87249) | 98.88th | v3 (v2023.03.01) |
| Dec 7, 2024 | 73.53% (0.73535) | 98.22th | v3 (v2023.03.01) |
| Nov 1, 2024 | 66.40% (0.66396) | 98.01th | v3 (v2023.03.01) |
| Sep 25, 2024 | 69.44% (0.69443) | 98.06th | v3 (v2023.03.01) |
| May 5, 2024 | 73.94% (0.73938) | 98.09th | v3 (v2023.03.01) |
| Mar 28, 2024 | 72.75% (0.72747) | 98.02th | v3 (v2023.03.01) |
| Nov 27, 2023 | 72.48% (0.72485) | 97.77th | v3 (v2023.03.01) |
| Oct 16, 2023 | 75.27% (0.75273) | 97.79th | v3 (v2023.03.01) |
| Jul 17, 2023 | 81.73% (0.81734) | 97.90th | v3 (v2023.03.01) |
| Apr 17, 2023 | 80.28% (0.80281) | 97.77th | v3 (v2023.03.01) |
| Mar 7, 2023 | 79.19% (0.79185) | 97.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 46.72% (0.46718) | 98.56th | v2 (v2022.01.01) |
| Oct 30, 2022 | 46.72% (0.46718) | 98.48th | v2 (v2022.01.01) |
| Aug 29, 2022 | 49.76% (0.49756) | 98.61th | v2 (v2022.01.01) |
| Jul 18, 2022 | 55.10% (0.55095) | 98.72th | v2 (v2022.01.01) |
| Jul 17, 2022 | 9.92% (0.09915) | 94.34th | v2 (v2022.01.01) |
| Jun 27, 2022 | 55.10% (0.55095) | 98.70th | v2 (v2022.01.01) |
| Apr 23, 2022 | 57.79% (0.57789) | 98.72th | v2 (v2022.01.01) |
| Feb 17, 2022 | 60.01% (0.60013) | 98.63th | v2 (v2022.01.01) |
| Feb 4, 2022 | 67.16% (0.67160) | 98.89th | v2 (v2022.01.01) |
References (14)
- http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx x_refsource_CONFIRMVendor Advisory
- http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx x_refsource_CONFIRMVendor Advisory
- http://isc.sans.org/diary.html?storyid=6481 x_refsource_MISCNot Applicable
- http://osvdb.org/54797 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/35268 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.microsoft.com/technet/security/advisory/971778.mspx x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/35139 vdb-entryx_refsource_BIDBroken Link
- http://www.securitytracker.com/id?1022299 vdb-entryx_refsource_SECTRACKBroken Link
- http://www.us-cert.gov/cas/techalerts/TA09-195A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2009/1445 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1886 vdb-entryx_refsource_VUPENVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028 vendor-advisoryx_refsource_MSVendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6237 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1537 government-resourceUS Government Resource
Change history (0)
No recorded changes yet.