Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5183

Опубликовано: 25 янв. 2020
Источник: nvd
CVSS3: 9
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:amd:atidxx64:26.20.13031.10003:*:*:*:*:*:*:*
cpe:2.3:a:amd:atidxx64:26.20.13031.15006:*:*:*:*:*:*:*
cpe:2.3:a:amd:atidxx64:26.20.13031.18002:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:15.0:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00482
Низкий

9 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-843

Связанные уязвимости

github
больше 3 лет назад

An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

EPSS

Процентиль: 65%
0.00482
Низкий

9 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-843