Impact
An uncontrolled DLL search path flaw exists in the AMD Vitis Unified Installer on Windows, which allows a malicious DLL placed in the installation directory to be loaded in place of a legitimate one. The injected code runs with the installer’s privileges, enabling arbitrary code execution and compromising the confidentiality, integrity, and availability of the host system. This vulnerability is classified as CWE‑427.
Affected Systems
The affected vendor is AMD and the product is the Vitis Unified Installer for FPGAs & Adaptive SoCs on Windows. All installations of this installer that have not applied the vendor’s patch remain vulnerable; specific version information was not disclosed, implying the issue may exist in current releases until a fix is deployed.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity, while the EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or remote through the placement of a malicious DLL in the installer’s directory, which the process will load automatically due to the insecure search order. An attacker who succeeds could achieve system‑level compromise if the installer runs with elevated rights.
OpenCVE Enrichment