CVE-2025-0041
Received
Received - Intake
Uncontrolled Search Path in Vitis Embedded SFD for Windows
Vulnerability report for CVE-2025-0041, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-08-11
Assigner: Advanced Micro Devices Inc.
Description
Description
Uncontrolled search paths in the Vitisβ’ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | vitis_embedded_single_file_download | 2026.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |