Executive brief
AMD Vitis Unified is a software development platform for designing applications on AMD FPGAs and Xilinx devices. Improper file permissions in the installation directory on Windows could allow an attacker with local user access to modify or replace files, potentially leading to arbitrary code execution with elevated privileges when the application runs.
Technical details
The vulnerability is a privilege escalation flaw caused by weak file system permissions on the Vitis Unified installation path on Windows systems. A low-privileged local user can exploit these weak permissions to replace or modify executable files or libraries before they are loaded by higher-privileged processes. The attack requires local file system access to the installation directory and does not require authentication or network reachability. Successful exploitation results in arbitrary code execution in the context of a higher-privileged process. This is a classic Windows privilege escalation via insecure file permissions (CWE-276).
Affected products
- AMD Vitis Unified
Timeline
- 2026-08-11: disclosed