CVE-2019-5049: Critical severity amd radeon 550 firmware vulnerability
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5049?
CVE-2019-5049 is a memory corruption vulnerability in the AMD ATIDXX64.DLL driver.
How does CVE-2019-5049 work?
CVE-2019-5049 can be exploited by providing a specially crafted pixel shader file, which can cause an out-of-bounds memory write.
What is the severity of CVE-2019-5049?
CVE-2019-5049 has a severity rating of 10, which is considered critical.
Which software versions are affected by CVE-2019-5049?
The affected software versions are 25.20.15031.5004 and 25.20.15031.9002 of the AMD ATIDXX64.DLL driver.
How can CVE-2019-5049 be fixed?
To fix CVE-2019-5049, users should update their AMD ATIDXX64.DLL driver to a patched version provided by AMD.