CVE-2025-48506: Uncontrolled Search Paths in Vitis Unified Windows Install Path Enables DLL Injectio
CVE-2025-48506 Published on August 11, 2026

Uncontrolled search paths in Vitis Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.

NVD

Vulnerability Analysis

CVE-2025-48506 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
ACTIVE

Weakness Type

What is a DLL preloading Vulnerability?

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

CVE-2025-48506 has been classified to as a DLL preloading vulnerability or weakness.


Affected Versions

AMD Vitis™ Unified Installer for FPGAs & Adaptive SoCs in Windows Version 2026.1 is unaffected by CVE-2025-48506