LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-1537: Microsoft DirectX NULL Byte Overwrite Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-1537 to its Known Exploited Vulnerabilities catalog on May 20, 2026, with a federal patch deadline of Jun 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a…

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow. This flaw could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. The issue matters for any environment that processes QuickTime media through DirectShow components, as successful exploitation can result in arbitrary code execution on the affected system.

How it works

The weakness is a NULL byte overwrite condition in the QuickTime Movie Parser Filter. An attacker supplies a crafted QuickTime media file that is parsed by quartz.dll within DirectShow. This triggers the overwrite during file handling and can lead to execution of attacker-controlled code. Specific exploit mechanics are not detailed in the available summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

This vulnerability affects Microsoft DirectX installations that include the DirectShow QuickTime Movie Parser Filter. Inventory systems for the presence of quartz.dll and any DirectShow-based media processing pipelines. Check application or system logs for evidence of QuickTime file handling. Exact affected versions and configurations are not provided in the summary and must be confirmed against the vendor advisory. Telemetry showing unexpected process behavior during media file parsing can indicate potential exploitation attempts.

How to remediate

Apply mitigations per vendor instructions as the primary step. Where an update is available, install the vendor-supplied fix for the affected DirectX components. Confirm the precise remediation details against the vendor advisory before deployment. After patching, verify that quartz.dll and related DirectShow filters have been updated on all relevant systems.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities in this class can lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · DirectX
Added to CISA KEVMay 20, 2026
Federal patch deadlineJun 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities