CVE-2025-8087
Awaiting Analysis Awaiting Analysis - Queue

AMD Power Design Manager DLL Hijacking Privilege Escalation

Vulnerability report for CVE-2025-8087, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Advanced Micro Devices Inc.

Description

A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd power_design_manager From 2026.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-8087 is a DLL hijacking vulnerability in AMD Power Design Manager. It allows a malicious local attacker to escalate privileges during the uninstallation process, potentially leading to arbitrary code execution.

Detection Guidance

Detection involves checking for vulnerable AMD Power Design Manager installations and monitoring uninstallation processes for unusual DLL loading. Review installed software versions and logs for PDM uninstallation events. No specific commands are provided in the available resources.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to gain higher privileges on your system, potentially executing arbitrary code. This could lead to unauthorized system control or data manipulation.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. The vulnerability involves local privilege escalation via DLL hijacking during uninstallation, which could lead to arbitrary code execution. Compliance implications would depend on how the affected software is used in regulated environments.

Mitigation Strategies

Monitor for AMD Power Design Manager updates and apply version 2026.1 or later of the PDM Software Un-Installer once released on June 23, 2026.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-8087. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart