Home Microsoft CVE-2009-1537
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to Microsoft

CVE-2009-1537

Exploited

Microsoft DirectX - QuickTime Movie Parser Filter

Microsoft CVSS 8.8 Updated May 29, 2026

Executive Risk Summary

"A vulnerability in the QuickTime Movie Parser Filter in Microsoft DirectX allows remote attackers to execute arbitrary code via a crafted QuickTime media file. This vulnerability affects Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2."

Anticipated Attack Path

  1. 1. Exploitation of the vulnerability in the QuickTime Movie Parser Filter
  2. 2. Execution of arbitrary code on the vulnerable system
  3. 3. Potential lateral movement and further exploitation

Am I Vulnerable?

  • Verify the presence of the vulnerability in Microsoft DirectX
  • Check for the existence of a crafted QuickTime media file
  • Monitor system logs for signs of exploitation

Operational Audit Arsenal

Target Type DLL
Target Asset quartz.dll
Standard Path C:\Windows\System32
PowerShell
# 🛠️ Senior Engineer Universal Audit
# Target: quartz.dll (DLL)
$Targets = 'quartz.dll'
$SearchPaths = @("$env:windir\System32", "$env:ProgramFiles", "${env:ProgramFiles(x86)}")

Get-ChildItem -Path $SearchPaths -Include $Targets -Recurse -ErrorAction SilentlyContinue | 
Select-Object FullName, @{Name="Version";Expression={$_.VersionInfo.ProductVersion}}

Patch Impact Forecast

Reboot Required Likely

Potential disruption to multimedia applications and services

Internal Work Notes

Apply Microsoft Security Advisory 971778 to patch the vulnerability in Microsoft DirectX

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Official Advisoryhttp://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx
Official Advisoryhttp://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx
Official Advisoryhttp://isc.sans.org/diary.html?storyid=6481
Official Advisoryhttp://osvdb.org/54797
Official Advisoryhttp://secunia.com/advisories/35268
MSRC Advisoryhttp://www.microsoft.com/technet/security/advisory/971778.mspx
Official Advisoryhttp://www.securityfocus.com/bid/35139
Official Advisoryhttp://www.securitytracker.com/id?1022299
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-195A.html
Official Advisoryhttp://www.vupen.com/english/advisories/2009/1445
Official Advisoryhttp://www.vupen.com/english/advisories/2009/1886
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6237
Official Advisoryhttp://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx
Official Advisoryhttp://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx
Official Advisoryhttp://isc.sans.org/diary.html?storyid=6481
Official Advisoryhttp://osvdb.org/54797
Official Advisoryhttp://secunia.com/advisories/35268
MSRC Advisoryhttp://www.microsoft.com/technet/security/advisory/971778.mspx
Official Advisoryhttp://www.securityfocus.com/bid/35139
Official Advisoryhttp://www.securitytracker.com/id?1022299
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-195A.html
Official Advisoryhttp://www.vupen.com/english/advisories/2009/1445
Official Advisoryhttp://www.vupen.com/english/advisories/2009/1886
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-028
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6237
Official Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1537

Related Microsoft Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.