Description
Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled DLL search path flaw exists in the AMD Vitis Unified Installer on Windows, which allows a malicious DLL placed in the installation directory to be loaded in place of a legitimate one. The injected code runs with the installer’s privileges, enabling arbitrary code execution and compromising the confidentiality, integrity, and availability of the host system. This vulnerability is classified as CWE‑427.

Affected Systems

The affected vendor is AMD and the product is the Vitis Unified Installer for FPGAs & Adaptive SoCs on Windows. All installations of this installer that have not applied the vendor’s patch remain vulnerable; specific version information was not disclosed, implying the issue may exist in current releases until a fix is deployed.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity, while the EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote through the placement of a malicious DLL in the installer’s directory, which the process will load automatically due to the insecure search order. An attacker who succeeds could achieve system‑level compromise if the installer runs with elevated rights.

Generated by OpenCVE AI on August 13, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to the latest version of the AMD Vitis Unified Installer once released.
  • Ensure that the installation directory is excluded from the system’s DLL search path by adjusting the PATH environment variable or relocating the installer to a trusted location.
  • Implement file system permissions or application whitelisting to restrict write access to the installer’s directory, allowing only the installer process to modify it.

Generated by OpenCVE AI on August 13, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd vitis Unified Installer
Vendors & Products Amd
Amd vitis Unified Installer

Thu, 13 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Paths Enabling DLL Injection and Arbitrary Code Execution in AMD Vitis Unified Installer on Windows

Wed, 12 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Paths Enabling DLL Injection and Arbitrary Code Execution in AMD Vitis Unified Installer on Windows

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-427
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Amd Vitis Unified Installer
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-08-12T13:15:21.897Z

Reserved: 2025-05-22T16:34:02.896Z

Link: CVE-2025-48506

cve-icon Vulnrichment

Updated: 2026-08-12T13:15:18.197Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:44.200

Modified: 2026-08-12T20:50:58.370

Link: CVE-2025-48506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:07Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element