Executive brief
Vitis Unified is a software development platform used by hardware engineers. An attacker with local access to a Windows machine can inject malicious DLL files into the Vitis installation directory, causing the software to execute arbitrary code when launched. This could allow an attacker to gain full control of the development system and any designs or intellectual property stored on it.
Technical details
The vulnerability is a DLL injection flaw caused by uncontrolled search paths in the Vitis Unified installation directory on Windows. An attacker with local access can place a malicious DLL in the installation path, which will be loaded instead of the legitimate library when the application searches for dependencies. The attack requires local file system access and occurs when Vitis Unified is executed. Successful exploitation results in arbitrary code execution with the privileges of the user running Vitis. Patches or mitigations should be available through AMD's security bulletin.
Affected products
- AMD Vitis Unified
Timeline
- 2026-08-11: disclosed