Altera High Level Synthesis Compiler DLL Planting Vulnerability

Vulnerability

A DLL planting vulnerability has been identified in the Altera High Level Synthesis Compiler for Windows, specifically in versions up to 24.3. This vulnerability arises from an uncontrolled search path element, allowing malicious DLLs to be planted and potentially executed. The issue is present in a batch file within a design example, and the Linux version of the compiler is not affected.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of malicious DLLs, potentially allowing for privilege escalation.

Remediation

Altera recommends replacing the build.bat file in the affected design example with a version that does not contain the vulnerability. Additionally, write access to the 'C:\quartus\bin64' directory should be restricted to system administrators only.

Added: Dec 12, 2025, 3:20 AM
Updated: Dec 12, 2025, 3:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
2.9
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.