PT-2026-48888 · Amd · Amd Optional Tools

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-40677

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AMD optional tools (affected versions not specified)
Description The use of insecure HTTP transport within the auto-updater allows for a man-in-the-middle attack, which is a technique where an attacker intercepts communication between two parties to steal or manipulate data. This flaw could potentially lead to arbitrary code execution, allowing an attacker to run unauthorized commands on the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-40677

Affected Products

Amd Optional Tools