Impact
The vulnerability arises from weak permissions on the Vitis™ Unified installation path. A local user with limited privileges can modify or create files in that directory, which can lead to the execution of arbitrary code. Because the affected binary runs with higher privileges, this flaw can result in binary hijacking and the compromise of system integrity.
Affected Systems
AMD Vitis™ Embedded Single File Download (SFD) for Windows. No specific version range is listed, but the issue applies to any installation of the package that does not enforce proper directory permissions.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. The EPSS score is below 1%, showing a low probability of exploitation at the time of this analysis. It is not included in the CISA KEV catalog. The flaw can be leveraged by an attacker who already has a non-administrative account on the host, and through manipulation of install directory files, can achieve privilege escalation and arbitrary code execution.
OpenCVE Enrichment