CVE-2009-1537

HIGH(8.8)KEVLikely Exploited

Microsoft DirectX NULL Byte Overwrite Vulnerability

Description

CVE-2009-1537, addressed by Microsoft bulletin MS09-028, is a high-severity remote code execution vulnerability in Microsoft DirectX. The flaw is a NULL byte overwrite in the QuickTime Movie Parser Filter inside quartz.dll, a component of DirectShow, and is triggered when a victim opens a crafted QuickTime media file. Successful exploitation lets a remote attacker execute arbitrary code in the context of the user who opened the file, making malicious media files and drive-by websites effective delivery vectors. With a CVSS score of 8.8, an EPSS score of 53% (98th percentile), confirmed exploitation in the wild in May 2009, and a CISA KEV listing, CVE-2009-1537 remains a meaningful risk on legacy Windows systems.

KEV Information

Vendor
Microsoft
Product
DirectX
Date Added
May 20, 2026
Due Date
June 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftdirectx7.0; 7.0a; 7.1; 8.1; 8.1b; 9.0; 9.0a; 9.0b; 9.0c
microsoftwindows 2000All versions
microsoftwindows 2003 serverAll versions
microsoftwindows server 2003All versions
microsoftwindows xp-

References

Weakness Type

CWE-158: Improper Neutralization of Null Byte or NUL Character

In the DirectShow QuickTime Movie Parser Filter (quartz.dll), improper handling of a NULL byte during media parsing leads to a NULL byte overwrite that corrupts memory, allowing an attacker to influence execution flow and run arbitrary code when a crafted QuickTime file is parsed.

Learn more: CWE-158 — Improper Neutralization of Null Byte or NUL Character

Impact Analysis

CVE-2009-1537 carries a CVSS 3.1 score of 8.8 (HIGH). It is remotely exploitable over the network with low attack complexity and requires no privileges, but it does require user interaction — the victim must open or be served a crafted QuickTime media file — and on success it fully compromises the confidentiality, integrity, and availability of the affected system in the context of the user. Because media files are routinely shared via email, downloads, and embedded web content, attackers can readily lure victims into triggering the flaw through drive-by or social-engineering delivery. The EPSS score of 53% (98th percentile) indicates a high probability of exploitation activity, and the CISA KEV listing confirms it was exploited in the wild, so any unpatched legacy Windows host with the vulnerable DirectShow component should be remediated.

Exploit Maturity

CVE-2009-1537 was exploited in the wild in May 2009, prompting Microsoft to issue Security Advisory 971778 and later the MS09-028 update. It is listed on the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 53% (98th percentile) signals a high likelihood of continued exploitation activity. No exploit-tagged proof-of-concept appears in the NVD references — the available sources are vendor advisories such as the Microsoft MSRC advisory and MS09-028 bulletin — but given the confirmed in-the-wild use and the age of the flaw, reliable exploitation techniques are well understood and any exposed legacy system should be patched.

Remediation

  1. Apply the MS09-028 update or remove the affected asset from the network as mandated by the CISA KEV deadline of 2026-06-03: install the DirectShow update from Microsoft Security Bulletin MS09-028 for all affected DirectX versions.
  2. For end-of-life systems (Windows 2000, Windows XP, Windows Server 2003) that can no longer be patched, isolate or decommission them rather than leaving them in service.
  3. As an interim mitigation, follow Microsoft Security Advisory 971778's guidance to disable parsing of QuickTime content by the QuickTime Movie Parser Filter (for example by modifying the relevant registry keys) until the update can be applied.
  4. Reduce exposure to malicious media by blocking or scanning inbound QuickTime files at email and web gateways, and advise users not to open untrusted media files.
  5. As long-term hardening, ensure exploit-mitigation features (DEP) are enabled, keep media-handling components updated, and migrate off unsupported operating systems where the vulnerable DirectShow component cannot be maintained.

Technical Details

CVE-2009-1537 is a memory-corruption vulnerability in the QuickTime Movie Parser Filter within quartz.dll, the DirectShow component of Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2/SP3, and Windows Server 2003 SP2. When DirectShow parses a crafted QuickTime media file, a NULL byte is improperly written (a NULL byte overwrite), corrupting memory in a way that an attacker can leverage to execute arbitrary code. The weakness maps to improper neutralization of a NULL byte (CWE-158) during media parsing. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) reflects a network-deliverable, low-complexity attack that requires user interaction to open the malicious file but then fully compromises the system, executing code with the privileges of the targeted user.

Frequently Asked Questions

Is CVE-2009-1537 being actively exploited?

Yes. CVE-2009-1537 was exploited in the wild in May 2009 and is listed on the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 53% (98th percentile) indicates a high probability of ongoing exploitation activity against unpatched legacy systems.

What products are affected by CVE-2009-1537?

The vulnerability affects Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, specifically the QuickTime Movie Parser Filter in the DirectShow component (quartz.dll).

How do I fix CVE-2009-1537?

Apply the Microsoft MS09-028 security update on all affected supported systems. As an interim measure, follow Microsoft Security Advisory 971778 to disable QuickTime parsing in DirectShow, and isolate or decommission any end-of-life systems that cannot be patched.

How severe is CVE-2009-1537?

CVE-2009-1537 is rated HIGH with a CVSS 3.1 score of 8.8. It enables remote code execution when a victim opens a crafted QuickTime media file, fully compromising the system in the user's context, and was confirmed exploited in the wild shortly after disclosure.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score51.21%
EPSS Percentile98.8%

Dates

PublishedMay 29, 2009
Last ModifiedJune 16, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.