AMD RadeonÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-19

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5049£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.0£¬¹Ù·½Î´ÆÀ¶¨


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


AMD ATIDXX64.DLL 25.20.15031.5004°æ±¾ºÍ25.20.15031.9002°æ±¾£¨ÔËÐÐÔÚRadeon RX 550 / 550 Series VMware Workstation 15 (15.0.4 build-12990004)°æ±¾ÉÏ£©


¡ñ·ì϶¸ÅÊö


AMD RadeonÏÔ¿¨µÄijЩÅäÖÃÖдæÔÚÃýÎ󣬿ÉÄÜÔÊÐí¹¥»÷Õß½ÚÔìÖ¸±êϵͳ¡£Äܹ»Í¨¹ýÏòAMD ATIDXX64.DLLÇý¶¯·¨Ê½ÌṩÌåʽÃýÎóµÄÏñËØ×ÅÉ«Æ÷£¨VMware guestÐé¹¹»ú²Ù×÷ϵͳÄÚ²¿£©À´´¥·¢´Ë·ì϶¡£ÕâÖÖ¹¥»÷Äܹ»´ÓVMwareÀ´±öÓû§Ä£Ê½´¥·¢£¬µ¼ÖÂÖ÷»úÉϵÄvmware-vmx.exe¹ý³ÌÄÚ´æ°Ü»µ£¬»òÀíÂÛÉÏͨ¹ýWEBGL£¨Ô¶³ÌÍøÕ¾£©µ¼ÖÂÄÚ´æ°Ü»µ¡£


Ò×Êܹ¥»÷µÄ´úÂ루sub_32B820£©Î»ÓÚAMD¿âATIDXX64.DLLÖУ¬Êǹ¥»÷ÕßÌṩµÄ×ÅÉ«Æ÷×Ö½ÚÂëÊý¾ÝµÄÖ¸±ê¡£ÓÉÓÚ²»×ãÊʵ±µÄÌìǵ²é³­£¬¹¥»÷ÕßÄܹ»²¿ÃŽÚÔìÖ¸±êµØÖ·µÄÍÆË㣬´Ó¶øµ¼ÖÂÊܿصÄÄÚ´æ°Ü»µ¡£Ê¹ÓöñÒâÏñËØ×ÅÉ«Æ÷£¬¹¥»÷Õß¿ÉÄܻᵼÖÂÔ½½çÄÚ´æÐ´Èë²»½öÓ°ÏìVM guestÐé¹¹»ú£¬»¹»áÓ°Ïìµ×²ãÖ÷»úϵͳ¡£


¡ñ·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.amd.com¡£


¡ñ²Î¿¼Á´½Ó


https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0818