CVE-2019-5049 is a critical memory corruption vulnerability in the AMD ATIDXX64.DLL driver, affecting specific versions of AMD Radeon 550 and RX 550 series products. A specially crafted pixel shader can trigger an out-of-bounds memory write, allowing an attacker to achieve a VMware guest-to-host escape. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no user interaction and enabling complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
25.20.15031.5004CPE matchmatch criteria | cpe:2.3:o:amd:radeon_rx_550_firmware:25.20.15031.5004:*:*:*:*:*:*:* | ||
25.20.15031.9002CPE matchmatch criteria | cpe:2.3:o:amd:radeon_rx_550_firmware:25.20.15031.9002:*:*:*:*:*:*:* | ||
25.20.15031.5004CPE matchmatch criteria | cpe:2.3:o:amd:radeon_550_firmware:25.20.15031.5004:*:*:*:*:*:*:* | ||
25.20.15031.9002CPE matchmatch criteria | cpe:2.3:o:amd:radeon_550_firmware:25.20.15031.9002:*:*:*:*:*:*:* | ||
25.20.15031.5004CPE matchmatch criteria | cpe:2.3:o:amd:radeon_rx_550x_firmware:25.20.15031.5004:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.