Sony Optical Disc Archive Software Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in Optical Disc Archive Software for Windows, versions 1.0.0 through 5.5.2, provided by Sony Corporation. The software registers a Windows service with an unquoted file path, creating a vulnerability that allows users with write permissions on the root directory of the system drive to execute arbitrary code with SYSTEM privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with SYSTEM privileges.

Remediation

Users are advised to update the software to the latest version. The latest version can be downloaded from the Sony Optical Disc Archive Software application page.

Added: Nov 5, 2025, 7:19 AM
Updated: Nov 5, 2025, 7:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.