CVE-2025-48506
Awaiting Analysis
Awaiting Analysis - Queue
Uncontrolled Search Path in AMD Vitis for Windows Leads to DLL Injection
Vulnerability report for CVE-2025-48506, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-08-12
Assigner: Advanced Micro Devices Inc.
Description
Description
Uncontrolled search paths in Vitisβ’ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | vitis | 2026.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |