Vulnerability record · CVE-2007-3901 · published 12 December 2007
CVE-2007-3901: Microsoft DirectX SAMI Parser Stack Buffer Overflow in quartz.dll
Microsoft · Directx
A stack-based buffer overflow exists in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll, affecting Microsoft DirectX 7.0 through 10.0. A crafted SAMI file can overflow a stack buffer, allowing remote code execution in the context of the parsing process. The flaw is remotely reachable and carries a high CVSS v2 score of 8.5.
Description
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.
AV:N/AC:M/Au:S/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with a CVSS v2 score of 8.5, public exploit code exists, and EPSS is very high, though it is not listed in CISA KEV.
What it is
A stack-based buffer overflow exists in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll, affecting Microsoft DirectX 7.0 through 10.0. A crafted SAMI file can overflow a stack buffer, allowing remote code execution in the context of the parsing process. The flaw is remotely reachable and carries a high CVSS v2 score of 8.5.
Impact
An attacker who successfully triggers the overflow can execute arbitrary code with the privileges of the user or application processing the SAMI file. This can lead to full compromise of confidentiality, integrity, and availability on the affected host.
Attack surface
The vulnerability is reached over the network by delivering a malicious SAMI file that is parsed by DirectShow. The CVSS vector (AV:N/AC:M/Au:S) indicates network delivery, medium attack complexity, and that some level of authentication or user context is required, with no explicit user interaction stated in the record.
Exploitation
The record does not list this CVE in CISA KEV and provides no ransomware association; EPSS shows a 30-day probability of 0.45873 (98.7th percentile), and a public Exploit-DB entry (4866) exists, indicating exploit code is publicly available.
What to do
- Apply the Microsoft security update MS07-064 for DirectX/quartz.dll as the primary fix.
- Block or restrict delivery of untrusted SAMI files through email, web, and file-sharing channels.
- Disable or unregister the SAMI/DirectShow parsing path where it is not operationally required.
- Enforce least privilege so that media parsing occurs under a low-privilege account.
- Monitor vendor advisories and CERT/CC guidance for any updated workarounds.
Detection
- Monitor for processes loading quartz.dll and subsequently spawning unexpected child processes or making network connections.
- Inspect email and web gateways for SAMI file attachments or downloads and alert on their presence.
- Use endpoint detection to flag crashes or memory corruption events in quartz.dll or DirectShow-related processes.
- Hunt for known public exploit artifacts associated with Exploit-DB 4866 in file or process telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3901 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3901), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.