CVE-2025-61970: Low severity AMD Vitis Unified Installation vulnerability
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
On local Windows machines, remediate weak permissions on the Vitis™ Unified installation path to prevent low-privileged users from creating files there (which could enable binary hijacking).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61970?
CVE-2025-61970 has a risk score of 43, indicating a moderate severity level.
How do I fix CVE-2025-61970?
To fix CVE-2025-61970, ensure that the permissions in the Vitis Unified installation path are properly configured to restrict low-privileged users.
What are the potential impacts of CVE-2025-61970?
The potential impact of CVE-2025-61970 includes a low-privileged user being able to create arbitrary code, leading to possible binary hijacking.
Who is affected by CVE-2025-61970?
CVE-2025-61970 affects users of the AMD Vitis Unified Installation software on local Windows machines.
When was CVE-2025-61970 published?
CVE-2025-61970 was published on August 11, 2026.