CVE-2009-1537CISA KEV
Microsoft DirectX NULL Byte Overwrite Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
- Product
- DirectX
- Added to KEV
- 20 May 2026
- Federal remediation due
- 3 Jun 2026
- Known ransomware use
- Not reported