9

CVE-2019-5183

An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Atidxx64 Version 26.20.13031.10003
   VMware ≫ Workstation Version 15.0
Amd ≫ Atidxx64 Version 26.20.13031.15006
   VMware ≫ Workstation Version 15.0
Amd ≫ Atidxx64 Version 26.20.13031.18002
   VMware ≫ Workstation Version 15.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.757
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://talosintelligence.com/vulnerability_reports/TALOS-2019-0964
Third Party Advisory