Impact
The vulnerability stems from improper file permissions in the Vitis Unified installation directory on Windows. A user with standard local privileges can replace or modify files in this path, enabling execution of arbitrary code with elevated rights. The weakness is classified as CWE‑276, indicating inappropriate access control on privileged files.
Affected Systems
The affected component is the AMD Vitis Unified Installer for FPGAs & Adaptive SoCs on Windows. No specific version numbers are provided in the available data.
Risk and Exploitability
The CVSS score of 7.3 marks the issue as high severity. The EPSS score of less than 1 % suggests that exploitation is currently unlikely. It is not listed in the CISA KEV catalog. Attackers would need local access to the Windows machine and the ability to write to the Vitis installation path; the attack vector is inferred to be local file‑system manipulation.
OpenCVE Enrichment