First published: Mon Jul 20 2020(Updated: )
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest using the RemoteFX feature, leading to executing the vulnerable code on the HYPER-V host (inside of the rdvgm.exe process). Theoretically this vulnerability could be also triggered from web browser (using webGL and webassembly).
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD Radeon DirectX 11 Driver | =26.20.15019.19000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6103 is considered a critical vulnerability that can lead to remote code execution.
To mitigate CVE-2020-6103, update the AMD Radeon DirectX 11 Driver to the latest version released by AMD.
CVE-2020-6103 specifically affects systems running AMD Radeon DirectX 11 Driver version 26.20.15019.19000.
CVE-2020-6103 is a code execution vulnerability that arises from issues in the Shader functionality.
Yes, CVE-2020-6103 can be exploited by attackers remotely through specially crafted shader files.