ZeroHour

CVE-2019-5049

CVSS 3.1
10.0 critical
EPSS
2%p80
Published
()
Modified
Description

An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

Vendors
amd
Products
radeon rx 550 firmware, radeon 550 firmware, radeon rx 550x firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news