Back to Database
Status published
High
CVE-2025-62225
Optical Disc Archive Software provided by Sony Corporation registers a...
Vulnerability Description
Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62225
Credits & Attribution
No credits recorded in the NVD database.
References
More from Sony Corporation
View All →CVE-2025-64772
The installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an...
High
8.4
CVE-2025-64730
Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this...
Medium
4.8
CVE-2025-62497
Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to...
Low
2.1
CVE-2022-41796
Untrusted search path vulnerability in the installer of Content Transfer...
Unknown
0
CVE-2021-20793
Untrusted search path vulnerability in the installer of Sony Audio...
High
7.8
Affected Vendor
Sony Corporation
View all reports →Affected Software
Optical Disc Archive Software (for Windows)
Vulnerable Versions:
1.0.0 to 5.5.2
Timeline
Official Publish:
November 5th, 2025
Last Modified:
November 5th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H