CVE-2025-48506
Awaiting Analysis Awaiting Analysis - Queue

Uncontrolled Search Path in AMD Vitis for Windows Leads to DLL Injection

Vulnerability report for CVE-2025-48506, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Advanced Micro Devices Inc.

Description

Uncontrolled search paths in Vitisβ„’ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd vitis 2026.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves uncontrolled search paths in AMD Vitis Unified installation on Windows machines. Attackers could exploit this by placing malicious DLL files in installation paths, leading to arbitrary code execution if the system searches these paths.

Impact Analysis

If exploited, this could allow attackers to run malicious code on your system with the same privileges as the vulnerable application. This might lead to data theft, system compromise, or further network infiltration depending on the application's permissions.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating data protection requirements under GDPR or HIPAA by enabling access to sensitive data. Organizations may face compliance violations if exploited.

Mitigation Strategies

Monitor for unauthorized DLLs in Vitis installation paths and restrict write permissions to installation directories. Apply AMD's official patches once available, particularly version 2026.1 or later.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-48506. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart