CVE-2025-62225
Optical Disc Archive Software provided by Sony Corporation registers a

Publication date: 2025-11-05

Last updated on: 2025-11-05

Assigner: [email protected]

Description
Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Affected Vendors & Products
Vendor Product Version
sony optical_disc_archive_software 5.5.2
sony optical_disc_archive_software 5.5.1
sony optical_disc_archive_software 1.0.0
sony optical_disc_archive_software 5.5.3
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-428 The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?


How can this vulnerability impact me? :


How can this vulnerability be detected on my network or system? Can you suggest some commands?


What immediate steps should I take to mitigate this vulnerability?


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart
Meta Information
CVE Publication Date:
2025-11-05
CVE Last Modified Date:
2025-11-05
Report Generation Date:
2025-11-06
AI Powered Q&A Generation:
2025-11-05
EPSS Last Evaluated Date:
2025-11-05
NVD Report Link: