AMDCVE-2025-48505
AMD: code execution
Low1.0CVE-2025-48505 · Published Aug 11, 2026 · updated Sep 23, 2026
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code execution.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-276
More AMD advisories
All AMD| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | AMD: privilege escalation | High7.0 | No fix yet |
| Aug 11 | AMD: untrusted search path | High7.0 | No fix yet |
| Aug 11 | AMD Ryzen Master Utility Driver: use after free | Medium5.6 | No fix yet |
| Aug 11 | AMD: timing side channel | High8.5 | No fix yet |
| Aug 11 | AMD: code execution | Medium4.6 | No fix yet |
| Aug 11 | AMD: insecure default permissions | Low1.0 | No fix yet |