What is CVE-2025-0041?
This vulnerability allows a low-privileged user to achieve arbitrary code execution via uncontrolled search paths during local Windows installation of the Vitis™ Embedded Single File Download (SFD). Immediate patching or restricting user-controlled directories in the search path is recommended to mitigate the risk.
Azərbaycanca: Bu zəiflik Vitis™ Embedded Single File Download (SFD) alətində Windows lokal quraşdırması zamanı `uncontrolled search path` səbəbindən aşağı səlahiyyətli istifadəçiyə özbaşına kod icrası imkanı verə bilər. Bu, hücumçunun sistemə müdaxiləsini asanlaşdırdığı üçün dərhal yamaq tətbiq edilməli və ya yol axtarış məhdudiyyətləri konfiqurasiya olunmalıdır.
FAQ2
Which product is affected by CVE-2025-0041?
This vulnerability affects the Vitis™ Embedded Single File Download (SFD) tool.
What can an attacker achieve by exploiting CVE-2025-0041?
An attacker can achieve arbitrary code execution as a low-privileged user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.