Impact
A DLL hijacking flaw exists in the uninstallation component of AMD Power Design Manager. During uninstall, the software loads an external DLL from a location that can be controlled by a local user. If an attacker places a malicious DLL in that path, the uninstaller will execute it with elevated privileges, allowing the attacker to run arbitrary code on the machine. The weakness leverages improper handling of DLL search paths, corresponding to CWE‑427.
Affected Systems
The vulnerability impacts the AMD Power Design Manager Software Un‑Installer. No specific product versions are listed in the data, so all releases of the uninstaller that include the flaw are considered affected until AMD publishes a patch or rollback.
Risk and Exploitability
The CVSS score of 7 denotes a high severity issue, indicating that exploitation can compromise system integrity. The EPSS score of <1% suggests that, as of this analysis, the likelihood of exploitation is low, but vulnerable systems remain at risk. The vulnerability is not listed in CISA KEV. It is a local privilege escalation vector, inferred from the requirement that an attacker must execute the uninstaller on the target system.
OpenCVE Enrichment