AMD RadeonÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-09-19¡ñ·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5049£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.0£¬¹Ù·½Î´ÆÀ¶¨
¡ñÓ°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
AMD ATIDXX64.DLL 25.20.15031.5004°æ±¾ºÍ25.20.15031.9002°æ±¾£¨ÔËÐÐÔÚRadeon RX 550 / 550 Series VMware Workstation 15 (15.0.4 build-12990004)°æ±¾ÉÏ£©
¡ñ·ì϶¸ÅÊö
AMD RadeonÏÔ¿¨µÄijЩÅäÖÃÖдæÔÚÃýÎ󣬿ÉÄÜÔÊÐí¹¥»÷Õß½ÚÔìÖ¸±êϵͳ¡£Äܹ»Í¨¹ýÏòAMD ATIDXX64.DLLÇý¶¯·¨Ê½ÌṩÌåʽÃýÎóµÄÏñËØ×ÅÉ«Æ÷£¨VMware guestÐé¹¹»ú²Ù×÷ϵͳÄÚ²¿£©À´´¥·¢´Ë·ì϶¡£ÕâÖÖ¹¥»÷Äܹ»´ÓVMwareÀ´±öÓû§Ä£Ê½´¥·¢£¬µ¼ÖÂÖ÷»úÉϵÄvmware-vmx.exe¹ý³ÌÄÚ´æ°Ü»µ£¬»òÀíÂÛÉÏͨ¹ýWEBGL£¨Ô¶³ÌÍøÕ¾£©µ¼ÖÂÄÚ´æ°Ü»µ¡£
Ò×Êܹ¥»÷µÄ´úÂ루sub_32B820£©Î»ÓÚAMD¿âATIDXX64.DLLÖУ¬Êǹ¥»÷ÕßÌṩµÄ×ÅÉ«Æ÷×Ö½ÚÂëÊý¾ÝµÄÖ¸±ê¡£ÓÉÓÚ²»×ãÊʵ±µÄÌìǵ²é³£¬¹¥»÷ÕßÄܹ»²¿ÃŽÚÔìÖ¸±êµØÖ·µÄÍÆË㣬´Ó¶øµ¼ÖÂÊܿصÄÄÚ´æ°Ü»µ¡£Ê¹ÓöñÒâÏñËØ×ÅÉ«Æ÷£¬¹¥»÷Õß¿ÉÄܻᵼÖÂÔ½½çÄÚ´æÐ´Èë²»½öÓ°ÏìVM guestÐé¹¹»ú£¬»¹»áÓ°Ïìµ×²ãÖ÷»úϵͳ¡£
¡ñ·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
¡ñ½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.amd.com¡£
¡ñ²Î¿¼Á´½Ó
https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0818


¾©¹«Íø°²±¸11010802024551ºÅ