ZeroHour

CVE-2019-5098

PoC
CVSS 3.1
8.6 high
EPSS
2%p80
Published
()
Modified
Description

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

Vendors
vmwareamd
Products
workstation, radeon rx 550 firmware, radeon 550 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news