Description
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from weak permissions on the Vitis™ Unified installation path. A local user with limited privileges can modify or create files in that directory, which can lead to the execution of arbitrary code. Because the affected binary runs with higher privileges, this flaw can result in binary hijacking and the compromise of system integrity.

Affected Systems

AMD Vitis™ Embedded Single File Download (SFD) for Windows. No specific version range is listed, but the issue applies to any installation of the package that does not enforce proper directory permissions.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity. The EPSS score is below 1%, showing a low probability of exploitation at the time of this analysis. It is not included in the CISA KEV catalog. The flaw can be leveraged by an attacker who already has a non-administrative account on the host, and through manipulation of install directory files, can achieve privilege escalation and arbitrary code execution.

Generated by OpenCVE AI on August 13, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install the latest AMD security update or patch that addresses permission weaknesses for Vitis SFD.
  • Manually set secure permissions on the Vitis Unified installation path to restrict write access to administrators only, ensuring that low-privileged users cannot create or modify executables.
  • Regularly audit the installation directory’s permissions and contents to detect any unauthorized changes or added files.

Generated by OpenCVE AI on August 13, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd vitis Embedded Single File Download
Vendors & Products Amd
Amd vitis Embedded Single File Download

Thu, 13 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Weak File Permissions Enable Low-Privileged User to Execute Arbitrary Code

Wed, 12 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Weak File Permissions Enable Low-Privileged User to Execute Arbitrary Code

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
CWE-732
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N'}


Subscriptions

Amd Vitis Embedded Single File Download
cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-08-12T13:16:09.077Z

Reserved: 2025-10-04T18:09:57.018Z

Link: CVE-2025-61970

cve-icon Vulnrichment

Updated: 2026-08-12T13:16:05.909Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:44.330

Modified: 2026-08-12T20:50:58.370

Link: CVE-2025-61970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:09Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions

  • CWE-732

    Incorrect Permission Assignment for Critical Resource