CVE-2019-5049
published 2019-10-31CVE-2019-5049: An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel…
PriorityP354critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
2.01%
78.7th percentile
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | radeon_550_firmware | — | — |
| amd | radeon_550_firmware | — | — |
| amd | radeon_rx_550_firmware | — | — |
| amd | radeon_rx_550_firmware | — | — |
| amd | radeon_rx_550x_firmware | — | — |
| amd | radeon_rx_550x_firmware | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
23rd September – Threat Intelligence Bulletin
blogs_checkpoint·2019-09-23·CVSS 8.8
CVE-2017-0144 [HIGH] 23rd September – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd September – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 23rd September 2019, please download our Threat Intelligence Bulletin
TOP ATTACKS AND BREACHES
Misconfigured Elasticsearch server holding personal information of more than 20 million Ecuadorian citizens has been found The server, located in Miami and owned by the Ecuadorian company Novaestrat, exposes full PII (Personally identifiable information), marital status, education, financial info and more of prob
Talos
Vulnerability Spotlight: AMD ATI Radeon ATIDXX64.DLL shader functionality remote code execution vulnerability
blogs_talos·2019-09-16·CVSS 10.0
[CRITICAL] Vulnerability Spotlight: AMD ATI Radeon ATIDXX64.DLL shader functionality remote code execution vulnerability
Piotr Bania of Cisco Talos discovered this vulnerability.
Some AMD Radeon cards contain a remote code execution vulnerability in their ATIDXX64.DLL driver. AMD produces the Radeon line of hardware, which includes graphics cards and graphics processing units. This specific vulnerability exists on the Radeon RX 550 and the 550 Series while running VMWare Workstation 15. An attacker could exploit this vulnerability by supplying a malformed pixel shared inside the VMware guest operating system to the driver. This could corrupt memory in a way that would allow the attacker to gain the ability to remotely execute code on the victim machine.
In accordance with our coordinated disclosure policy, Cisco Talos worked with AMD to ensure that these issues are resolved and that an update is available
Talos
Vulnerability Spotlight: AMD ATI Radeon ATIDXX64.DLL shader functionality remote code execution vulnerability
blogs_talos·2019-09-16·CVSS 10.0
[CRITICAL] Vulnerability Spotlight: AMD ATI Radeon ATIDXX64.DLL shader functionality remote code execution vulnerability
## Vulnerability Spotlight: AMD ATI Radeon ATIDXX64.DLL shader functionality remote code execution vulnerability
Piotr Bania of Cisco Talos discovered this vulnerability.
Some AMD Radeon cards contain a remote code execution vulnerability in their ATIDXX64.DLL driver. AMD produces the Radeon line of hardware, which includes graphics cards and graphics processing units. This specific vulnerability exists on the Radeon RX 550 and the 550 Series while running VMWare Workstation 15. An attacker could exploit this vulnerability by supplying a malformed pixel shared inside the VMware guest operating system to the driver. This could corrupt memory in a way that would allow the attacker to gain the ability to remotely execute code on the victim machine.
In accordance with our coordinated disclo
2019-10-31
Published