CVE-2025-0041
Awaiting Analysis Awaiting Analysis - Queue

Uncontrolled Search Path in Vitis Embedded SFD for Windows

Vulnerability report for CVE-2025-0041, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Advanced Micro Devices Inc.

Description

Uncontrolled search paths in the Vitisβ„’ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd vitis_embedded_single_file_download 2026.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves uncontrolled search paths in the Vitisβ„’ Embedded Single File Download (SFD) for local Windows installations. A low-privileged user could exploit this to execute arbitrary code on the affected system.

Detection Guidance

Detection involves checking for the presence of Vitis Embedded SFD on Windows systems and verifying version numbers. Look for the installed software in Program Files and check if the version is below 2026.1. Monitor for unusual executable paths or unexpected file modifications in directories where Vitis SFD operates.

Impact Analysis

An attacker with low privileges could run malicious code on your system, potentially leading to unauthorized access, data theft, or system compromise. This could affect confidentiality, integrity, and availability of your data.

Compliance Impact

The vulnerability involves uncontrolled search paths allowing arbitrary code execution, which could lead to unauthorized data access or modification. This may impact compliance with standards like GDPR (data protection) or HIPAA (health information security) by increasing risks of data breaches or unauthorized system access.

Mitigation Strategies

Monitor AMD's official security bulletin for the upcoming mitigation in Vitis Embedded SFD version 2026.1. Until then, restrict user privileges and avoid installing untrusted software.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-0041. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart