Knox CVE Database
/
CVE-2009-1537
Critical
9.3

CVE-2009-1537: Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

Added to the CISA KEV catalog:
May 20, 2026

Overview

A null byte overwrite flaw in the QuickTime Movie Parser Filter within DirectShow's quartz.dll affects Microsoft DirectX versions 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2. An attacker who delivers a crafted QuickTime media file to a user on an affected system can achieve arbitrary code execution at that user's privilege level. The flaw was confirmed exploited in the wild in May 2009.

Vulnerability details

Affected vendor
Microsoft
Affected product
DirectX
Weakness type (CWE)
CWE-158

The QuickTime Movie Parser Filter in quartz.dll fails to properly neutralize a null byte embedded in a crafted QuickTime media file, a weakness class (CWE-158) where attacker-controlled input containing a null byte causes the parser to misinterpret size fields or pointer values. The fix Microsoft issued corrects how DirectShow validates those pointer values and size fields during QuickTime file parsing. When the parser processes the malformed data, it performs an incorrect memory write, corrupting process memory in a way that can redirect execution.


An attacker delivers a specially crafted QuickTime media file to a target user, through email, a web download, or a malicious site, and waits for the user to open it. Opening the file causes DirectShow to invoke the vulnerable parser, triggering the null byte overwrite. The attacker gains code execution at the privilege level of the logged-in user. On systems where the user holds administrative rights, this results in full system compromise. User interaction is required: the victim must open the malicious file.

Severity and impact

9.3
Critical
AV:N/AC:M/Au:N/C:C/I:C/A:C
Attack vector
Network
Attack complexity
Medium
Privileges required
User interaction
Scope
Confidentiality impact
Complete
Integrity impact
Complete
Availability impact
Complete

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor for unexpected child processes spawned by media-handling processes such as quartz.dll host processes (e.g., Windows Media Player, Internet Explorer) on Windows 2000, XP, or Server 2003 systems, particularly processes that have no corresponding user-initiated action.
  • Look for application crash events or Windows Error Reporting entries in the event log referencing quartz.dll or DirectShow components, which may indicate failed exploitation attempts against the QuickTime parser.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 3, 2026

Additional hardening

  • Apply Microsoft Security Bulletin MS09-028, which delivers the patched quartz.dll for affected DirectX versions on Windows 2000 SP4, Windows XP SP2/SP3, and Windows Server 2003 SP2. See the vendor advisory listed in References for download links by platform.
  • Restrict or block delivery of QuickTime media files (.mov, .qt) at email gateways and web proxies to reduce the attack surface for file-based delivery vectors.
  • Where QuickTime media playback is not required, use Windows access controls or software restriction policies to prevent quartz.dll from loading the QuickTime Movie Parser Filter.
  • Ensure users on affected systems operate with standard (non-administrative) accounts to limit the impact of successful exploitation to user-level privileges rather than full system compromise.

Key dates

Published (NVD)
May 29, 2009
Added to CISA KEV
May 20, 2026
Remediation deadline
June 3, 2026
Last updated
June 16, 2026

References

Frequently asked questions

Does CVE-2009-1537 affect my FedRAMP authorization?

If Microsoft DirectX runs inside your authorization boundary, yes. CVE-2009-1537 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 3, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency right now. Your options are to remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2009-1537?

Knox does not patch your software. Remediating Microsoft DirectX is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage that support your documentation posture heading into the next assessment. Applying the fix is yours to own; managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. For a CVE like CVE-2009-1537, that means exposure surfaces during continuous monitoring rather than only when an assessor flags it at review time, giving you the earliest possible opportunity to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2009-1537's remediation deadline of June 3, 2026 has passed. What happens now?

If CVE-2009-1537 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.