AMD Optional Tools OpenSSL Init DLL Injection (CVE-2025-62628)
CVE-2025-62628 Published on May 14, 2026

Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially resulting in arbitrary code execution.

NVD

Weakness Type

What is a DLL preloading Vulnerability?

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

CVE-2025-62628 has been classified to as a DLL preloading vulnerability or weakness.


Affected Versions

AMD AIM-T Manageability Service: AMD Cloud Manageability Service (ACMS): AMD Management Plug-In for SCCM: AMD Management Console (AMC): AMD Manageability API: AMD DASH CLI - Command Line Application: