CVE-2020-6102
CRITICALAMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000 - Out-of-bounds Write via Shader File
Title source: llmDescription
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability can be triggered from a HYPER-V guest using the RemoteFX feature, leading to executing the vulnerable code on the HYPER-V host (inside of the rdvgm.exe process). Theoretically this vulnerability could be also triggered from web browser (using webGL and webassembly).
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1042
Scores
CVSS v3
9.9
EPSS
0.0093
EPSS Percentile
76.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (1)
amd/radeon_directx_11_driver_atidxx64.dll
26.20.15019.19000
Published
Jul 20, 2020
Tracked Since
Feb 18, 2026