Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
Use CWE-94, Microsoft vendor hub and Directx product page to widen CVE-2010-1880 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2012-1537, CVE-2010-1879 and CVE-2009-1539 for nearby disclosures in the same product family. Additional editorial context is available in Weekly Security Roundup: Navigating the April 2026 Threat Landscape and Critical Framework Exploits.