First published: Thu Oct 31 2019(Updated: )
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amd Radeon Rx 550 Firmware | =25.20.15031.5004 | |
Amd Radeon Rx 550 Firmware | =25.20.15031.9002 | |
Amd Radeon Rx 550 | ||
Amd Radeon 550 Firmware | =25.20.15031.5004 | |
Amd Radeon 550 Firmware | =25.20.15031.9002 | |
Amd Radeon 550 | ||
Amd Radeon Rx 550x Firmware | =25.20.15031.5004 | |
Amd Radeon Rx 550x Firmware | =25.20.15031.9002 | |
Amd Radeon Rx 550x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5049 is a memory corruption vulnerability in the AMD ATIDXX64.DLL driver.
CVE-2019-5049 can be exploited by providing a specially crafted pixel shader file, which can cause an out-of-bounds memory write.
CVE-2019-5049 has a severity rating of 10, which is considered critical.
The affected software versions are 25.20.15031.5004 and 25.20.15031.9002 of the AMD ATIDXX64.DLL driver.
To fix CVE-2019-5049, users should update their AMD ATIDXX64.DLL driver to a patched version provided by AMD.