DLL Injection Vulnerability in Vitis™ Unified by AMD
CVE-2025-48506

7.3HIGH

What is CVE-2025-48506?

A vulnerability exists in the Vitis™ Unified installation path on local Windows systems, where uncontrolled search paths can be exploited. This flaw could permit unauthorized DLL injection into the installation directories, thereby enabling potential execution of arbitrary code. Users employing Vitis™ Unified should ensure their systems are adequately secured against such vulnerabilities to mitigate risks of exploitation.

Affected Version(s)

Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows 2026.1

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.