CVE-2019-5183 is a critical type confusion vulnerability in the AMD ATIDXX64.DLL driver, affecting specific versions and impacting both AMD and VMware products. An attacker can exploit this by providing a specially crafted pixel shader, which can lead to remote code execution on the host system, even from a VMware guest. With a CVSS score of 9.0 (CRITICAL), this vulnerability has a high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. Currently, there is no public exploit code available, and it has not been observed in active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
26.20.13031.10003CPE matchmatch criteria | cpe:2.3:a:amd:atidxx64:26.20.13031.10003:*:*:*:*:*:*:* | ||
26.20.13031.15006CPE matchmatch criteria | cpe:2.3:a:amd:atidxx64:26.20.13031.15006:*:*:*:*:*:*:* | ||
26.20.13031.18002CPE matchmatch criteria | cpe:2.3:a:amd:atidxx64:26.20.13031.18002:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.