Executive brief
AMD Vitis Unified, a development tool for hardware and software co-design, contains weak file permissions in its Windows installation directory. A low-privileged user on the same machine could exploit this to write malicious code into the installation path, potentially hijacking executable binaries and gaining elevated privileges or executing arbitrary code.
Technical details
The vulnerability is a privilege escalation issue stemming from improper file system permissions on the Vitis Unified installation directory on Windows. A low-privileged local user can create or modify files within the installation path due to overly permissive directory access controls. An attacker can leverage this to perform binary hijacking—replacing legitimate executables or libraries with malicious versions that execute when invoked by a higher-privileged process or user. The attack requires local access to the Windows machine where Vitis Unified is installed.
Affected products
- AMD Vitis Unified
Timeline
- 2026-08-11: disclosed