Description
A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.
Published: 2026-08-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a DLL hijacking flaw in the AMD Ryzen Master installation that enables a local user with sufficient privileges to place a malicious DLL in the firmware’s default load path. By doing so, the attacker can gain elevated privileges and execute arbitrary code with the same permissions as the Ryzen Master process. The weakness is cataloged as CWE‑427, indicating path‐related tampering.

Affected Systems

The risky components are AMD Ryzen Master for all processor families, the AMD Ryzen Master product designed for the Ryzen 3000 Series processors, and the AMD Ryzen Master SDK. No specific version information is available.

Risk and Exploitability

The CVSS score of 7 reflects a significant chance of privilege escalation, while the EPSS value of less than 1% indicates that exploitation is considered unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers need local executable access to the system in order to place the malicious DLL; thus it is a local‑user attack vector with moderate likelihood of success but potentially severe impact if successful.

Generated by OpenCVE AI on August 12, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AMD Ryzen Master to the latest release that fixes the DLL loading issue.
  • Remove or restrict write permissions to the AMD Ryzen Master DLL directory so that only administrative accounts can modify it.
  • As a temporary workaround, move the installation folder to a location with hardened ACLs or delete the vulnerable DLL if the latest update is not yet available.

Generated by OpenCVE AI on August 12, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd ryzen 3000 Series Processors
Amd ryzen Master
Amd ryzen Master Sdk
Vendors & Products Amd
Amd ryzen 3000 Series Processors
Amd ryzen Master
Amd ryzen Master Sdk

Wed, 12 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title DLL Hijacking in AMD Ryzen Master Allows Local Privilege Escalation

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.
Weaknesses CWE-427
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Amd Ryzen 3000 Series Processors Ryzen Master Ryzen Master Sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-08-12T13:12:56.246Z

Reserved: 2025-07-23T15:01:52.882Z

Link: CVE-2025-54512

cve-icon Vulnrichment

Updated: 2026-08-12T13:12:48.056Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T18:17:17.557

Modified: 2026-08-12T20:50:58.370

Link: CVE-2025-54512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:55Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element