AMD RadeonÇý¶¯·¨Ê½Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-19

¡ñ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5049 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.0 £¬¹Ù·½Î´ÆÀ¶¨


¡ñÓ°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


AMD ATIDXX64.DLL 25.20.15031.5004°æ±¾ºÍ25.20.15031.9002°æ±¾£¨ÔËÐÐÔÚRadeon RX 550 / 550 Series VMware Workstation 15 (15.0.4 build-12990004)°æ±¾ÉÏ£©


¡ñ·ì϶¸ÅÊö


AMD RadeonÏÔ¿¨µÄijЩÅäÖÃÖдæÔÚÃýÎó £¬¿ÉÄÜÔÊÐí¹¥»÷Õß½ÚÔìÖ¸±êϵͳ¡£Äܹ»Í¨¹ýÏòAMD ATIDXX64.DLLÇý¶¯·¨Ê½ÌṩÌåʽÃýÎóµÄÏñËØ×ÅÉ«Æ÷£¨VMware guestÐé¹¹»ú²Ù×÷ϵͳÄÚ²¿£©À´´¥·¢´Ë·ì϶¡£ÕâÖÖ¹¥»÷Äܹ»´ÓVMwareº£¶«Óû§Ä£Ê½´¥·¢ £¬µ¼ÖÂÖ÷»úÉϵÄvmware-vmx.exe¹ý³ÌÄÚ´æ°Ü»µ £¬»òÀíÂÛÉÏͨ¹ýWEBGL£¨Ô¶³ÌÍøÕ¾£©µ¼ÖÂÄÚ´æ°Ü»µ¡£


Ò×Êܹ¥»÷µÄ´úÂ루sub_32B820£©Î»ÓÚAMD¿âATIDXX64.DLLÖÐ £¬Êǹ¥»÷ÕßÌṩµÄ×ÅÉ«Æ÷×Ö½ÚÂëÊý¾ÝµÄÖ¸±ê¡£ÓÉÓÚ²»×ãÊʵ±µÄÌìǵ²é³­ £¬¹¥»÷ÕßÄܹ»²¿ÃŽÚÔìÖ¸±êµØÖ·µÄÍÆËã £¬´Ó¶øµ¼ÖÂÊܿصÄÄÚ´æ°Ü»µ¡£Ê¹ÓöñÒâÏñËØ×ÅÉ«Æ÷ £¬¹¥»÷Õß¿ÉÄܻᵼÖÂÔ½½çÄÚ´æÐ´Èë²»½öÓ°ÏìVM guestÐé¹¹»ú £¬»¹»áÓ°Ïìµ×²ãÖ÷»úϵͳ¡£


¡ñ·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


¡ñ½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttps://www.amd.com¡£


¡ñ²Î¿¼Á´½Ó


https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0818