Staff member
Malware Hunter
Multiple vulnerabilities exist in a driver associated with the AMD Radeon line of graphics cards. An attacker can exploit these bugs by providing a specially crafted shader file to the user while using VMware Workstation 15. These attacks can be triggered from VMware guest usermode to cause a variety of errors, potentially allowing an attacker to cause a denial-of-service condition or gain the ability to remotely execute code.
Talos tested and confirmed that these vulnerabilities affect AMD ATIDXX64.DLL, version 26.20.13025.10004 running on the Radeon RX 550 series of graphics cards, while running on VMware Workstation 15, version 15.5.0, build-14665864 with Windows 10 x64 running as the guestVM.