AMDCVE-2025-48506
AMD: code execution
Medium4.6CVE-2025-48506 · Published Aug 11, 2026 · updated Aug 12, 2026
Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-427
More AMD advisories
All AMD| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | AMD: privilege escalation | High7.0 | No fix yet |
| Aug 11 | AMD: untrusted search path | High7.0 | No fix yet |
| Aug 11 | AMD Ryzen Master Utility Driver: use after free | Medium5.6 | No fix yet |
| Aug 11 | AMD: timing side channel | High8.5 | No fix yet |
| Aug 11 | AMD: code execution | Low1.0 | No fix yet |
| Aug 11 | AMD: insecure default permissions | Low1.0 | No fix yet |