Description
Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper setting of directory permissions in the AMD Power Design Manager (PDM) installer for Windows allows a local user to overwrite files that are normally restricted to administrators. The vulnerability, identified as CWE‑732 (Wrong Permission Assignment for Critical Resource), can be leveraged by a non‑privileged user to gain elevated rights and potentially execute arbitrary code with system-level privileges.

Affected Systems

The issue occurs in the Windows installer component of AMD Power Design Manager (PDM). The affected releases are all installers that were distributed before the vendor’s fix, as the exact version numbers are not specified in the advisory, so any pre‑patched version is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7 indicates a medium‑to‑high severity. The EPSS score of less than 1 % suggests that active exploitation is currently uncommon, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires a local, logged‑on user; the misconfigured permissions provide a direct escalation path to administrator privileges.

Generated by OpenCVE AI on August 13, 2026 at 02:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Monitor the AMD security bulletin for an update that corrects the installer permissions.
  • When an updated installer is released, reinstall AMD Power Design Manager to replace the vulnerable executable.
  • Until a patch is available, restrict access to the existing installer directory by applying ACLs that deny write and execute rights to standard users and grant them only to administrators.
  • If possible, relocate the installer to a secure folder that is not accessible to ordinary users.

Generated by OpenCVE AI on August 13, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd amd Power Design Manager (pdm) Software Installer For Windows
Vendors & Products Amd
Amd amd Power Design Manager (pdm) Software Installer For Windows

Thu, 13 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Incorrect Installer Directory Permissions in AMD Power Design Manager

Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Incorrect Installer Directory Permissions in AMD Power Design Manager

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Amd Amd Power Design Manager (pdm) Software Installer For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-08-12T13:14:12.792Z

Reserved: 2024-11-21T16:18:14.725Z

Link: CVE-2025-0046

cve-icon Vulnrichment

Updated: 2026-08-12T13:14:09.632Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T18:17:17.420

Modified: 2026-08-12T20:50:58.370

Link: CVE-2025-0046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:53:54Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource