CVE-2025-54519

7.3

AMD · Vivado Documentation Navigator

A DLL hijacking vulnerability in the AMD Vivado Documentation Navigator for Windows allows local attackers to achieve privilege escalation and arbitrary code execution.

Executive summary

A high-severity DLL hijacking flaw in the AMD Vivado Documentation Navigator allows local attackers to escalate privileges and execute arbitrary code on affected Windows systems.

Vulnerability

This vulnerability, categorized as CWE-427 (Uncontrolled Search Path Element), occurs when the application improperly handles DLL loading. A local attacker with low privileges can leverage this flaw to hijack the search path, leading to local privilege escalation.

Business impact

The ability for a local attacker to achieve arbitrary code execution poses a severe risk to system integrity and confidentiality. By escalating privileges, an attacker could gain full control over the local machine, potentially facilitating lateral movement within the network or accessing sensitive intellectual property managed by the engineering software. The CVSS score of 7.3 reflects the significant impact on system security, despite the requirement for local access.

Remediation

Immediate Action: As AMD has indicated that no fix is currently planned for this installation, organizations should restrict local access to the affected systems and monitor for unauthorized software execution.

Proactive Monitoring: Security teams should implement endpoint detection and response (EDR) solutions to monitor for suspicious process creation or unusual DLL loading patterns initiated by the application.

Compensating Controls: Apply strict Principle of Least Privilege (PoLP) policies to ensure that standard users do not have unnecessary write access to the application directory or the system folders where DLL search path hijacking occurs.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given that AMD has confirmed no fix is planned, users must treat this as a permanent configuration risk. Organizations using the Vivado Documentation Navigator on Windows should isolate these systems from critical network segments or enforce stringent local access controls to prevent unauthorized users from exploiting the search path vulnerability.

More AMD CVEs

Sources

Originally found and disclosed by Reported through AMD Bug Bounty Program, per the CVE Program record.