Impact
An improper setting of directory permissions in the AMD Power Design Manager (PDM) installer for Windows allows a local user to overwrite files that are normally restricted to administrators. The vulnerability, identified as CWE‑732 (Wrong Permission Assignment for Critical Resource), can be leveraged by a non‑privileged user to gain elevated rights and potentially execute arbitrary code with system-level privileges.
Affected Systems
The issue occurs in the Windows installer component of AMD Power Design Manager (PDM). The affected releases are all installers that were distributed before the vendor’s fix, as the exact version numbers are not specified in the advisory, so any pre‑patched version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high severity. The EPSS score of less than 1 % suggests that active exploitation is currently uncommon, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires a local, logged‑on user; the misconfigured permissions provide a direct escalation path to administrator privileges.
OpenCVE Enrichment