CVE-2007-3901

Microsoft Directx - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16442
exploitdb WORKING POC VERIFIED
by ryujin · pythonremotewindows
https://www.exploit-db.com/exploits/4866
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/ms07_064_sami.rb

Scores

EPSS 0.7746
EPSS Percentile 99.0%

Details

CWE
CWE-119
Status published
Products (15)
microsoft/directx 5.2
microsoft/directx 6.1
microsoft/directx 7.0
microsoft/directx 7.0a
microsoft/directx 7.1
microsoft/directx 8.0
microsoft/directx 8.0a
microsoft/directx 8.1
microsoft/directx 8.1a
microsoft/directx 8.1b
... and 5 more
Published Dec 12, 2007
Tracked Since Feb 18, 2026