Junglewise Threat Intelligence

CVE-2025-0041: AMD Vitis Embedded uncontrolled search path privilege escalation

CVE-2025-0041 · Severity: info · Published 2026-08-11

Vendors: Amd.

Executive brief

Vitis Embedded is AMD's development environment for embedded systems. A flaw in the Single File Download (SFD) installer on Windows allows a low-privileged user to execute arbitrary code by manipulating the application's search paths, potentially leading to full system compromise through privilege escalation.

Technical details

The vulnerability is a classic uncontrolled search path / DLL hijacking issue in the Vitis Embedded SFD installer for Windows. An attacker with local user access can place malicious libraries in predictable search paths that the installer checks before legitimate system directories, causing the installer to load and execute attacker-controlled code during installation. The attack requires local access and occurs during the installation process. An authenticated local attacker can achieve arbitrary code execution with the privileges of the installer process, potentially system-level code execution if the installer runs elevated.

Affected products

  • AMD Vitis Embedded <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References