CVE-2009-1537 describes an unspecified vulnerability within the QuickTime Movie Parser Filter (quartz.dll) in Microsoft DirectX versions 7.0 through 9.0c, affecting Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2. This flaw allows remote attackers to execute arbitrary code by enticing a user to open a specially crafted QuickTime media file. With a CVSS score of 9.3, this vulnerability is critical, indicating a network-based attack with medium complexity that can lead to complete compromise of confidentiality, integrity, and availability. Although exploited in the wild in May 2009, there is no public exploit code available in Metasploit or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:a:microsoft:directx:7.0:*:*:*:*:*:*:* | ||
7.0aCPE matchmatch criteria | cpe:2.3:a:microsoft:directx:7.0a:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:microsoft:directx:7.1:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:microsoft:directx:8.1:*:*:*:*:*:*:* | ||
8.1bCPE matchmatch criteria | cpe:2.3:a:microsoft:directx:8.1b:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.