Impact
The vulnerability arises from uncontrolled search paths in the Vitis Embedded Single File Download (SFD) for Windows, allowing a local user with low privileges to achieve arbitrary code execution on the host system. The flaw is a type of insecure path manipulation (CWE‑427), which can lead to full compromise of the target machine once exploited. The attack results in the attacker gaining capabilities to run malicious code, elevate privileges or modify system state.
Affected Systems
All local installations of AMD Vitis Embedded Single File Download for Windows may be affected. Specific version details were not disclosed in the source data, so any deployment of the application is potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, but the EPSS score of <1% suggests that real-world exploitation is unlikely at present and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an adversary must be able to log onto the system with a non‑administrator account or otherwise obtain local access. Given these constraints, the risk to highly secure environments remains limited, but the potential impact warrants timely remediation.
OpenCVE Enrichment