Sony Optical Disc Archive Software Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A vulnerability exists in Optical Disc Archive Software for Windows, versions 1.0.0 through 5.5.2, provided by Sony Corporation. The software registers a Windows service with an unquoted file path, creating a vulnerability that allows users with write permissions on the root directory of the system drive to execute arbitrary code with SYSTEM privileges.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of code with SYSTEM privileges.
Remediation
Users are advised to update the software to the latest version. The latest version can be downloaded from the Sony Optical Disc Archive Software application page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
