CNNVD-202511-436 Information

CNNVD ID

CNNVD-202511-436

CVE-2025-62225

  • CNNVD Published: 2025-11-05

Description (Chinese)

Sony Optical Disc Archive Software是日本索尼(Sony)公司的一个用于长期归档和数据存储的系统。 Sony Optical Disc Archive Software存在代码问题漏洞,该漏洞源于Windows服务注册了未加引号的文件路径,可能导致具有系统驱动器根目录写入权限的用户以SYSTEM权限执行任意代码。

Description (English)

Sony Optical Disc Archive Software is a long-term archiving and data storage system of Sony Japan. Sony Optical Disc Archive Software has a code loophole, which stems from the Windows service’s registration of unquoted file paths, which may result in any user with SYSTEM permission to write to a system drive root directory.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

索尼

Published

2025-11-05

Last Modified

2026-02-24

References

https://www.sony.jp/oda/application/?srsltid=AfmBOoo8t7k-alQo7ZnV2MAhq8qfIJtFOJN41U2Tu-B1yrpx3Y_KHurk https://jvn.jp/en/jp/JVN81917433/ https://access.redhat.com/security/cve/cve-2025-62225

Patch

https://www.sony.jp/oda/application/?srsltid=AfmBOoo8t7k-alQo7ZnV2MAhq8qfIJtFOJN41U2Tu-B1yrpx3Y_KHurk

Share on: