Description
Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from uncontrolled search paths in the Vitis Embedded Single File Download (SFD) for Windows, allowing a local user with low privileges to achieve arbitrary code execution on the host system. The flaw is a type of insecure path manipulation (CWE‑427), which can lead to full compromise of the target machine once exploited. The attack results in the attacker gaining capabilities to run malicious code, elevate privileges or modify system state.

Affected Systems

All local installations of AMD Vitis Embedded Single File Download for Windows may be affected. Specific version details were not disclosed in the source data, so any deployment of the application is potentially vulnerable until a fix is applied.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, but the EPSS score of <1% suggests that real-world exploitation is unlikely at present and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an adversary must be able to log onto the system with a non‑administrator account or otherwise obtain local access. Given these constraints, the risk to highly secure environments remains limited, but the potential impact warrants timely remediation.

Generated by OpenCVE AI on August 13, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update released by AMD for the Vitis Embedded SFD product
  • Configure the system to use a restricted, explicitly set search path for the application, removing any directory entries that can be influenced by the user
  • Enforce least privilege on the Windows installation directory, restricting read and execute permissions to administrators only
  • Use Windows AppLocker or similar application control policies to block execution of unapproved binaries within the SFD directories

Generated by OpenCVE AI on August 13, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd vitis Embedded Single File Download
Vendors & Products Amd
Amd vitis Embedded Single File Download

Thu, 13 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Path Allows Local Code Execution in Vitis Embedded SFD

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Path Allows Local Code Execution in Vitis Embedded SFD

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-427
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Amd Vitis Embedded Single File Download
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-08-12T13:16:56.601Z

Reserved: 2024-11-21T16:18:08.715Z

Link: CVE-2025-0041

cve-icon Vulnrichment

Updated: 2026-08-12T13:16:47.610Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:42.140

Modified: 2026-08-12T20:50:58.370

Link: CVE-2025-0041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:10Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element