Executive brief
Sony Optical Disc Archive Software, used for managing high-capacity data storage, contains a security flaw in its Windows installer. An attacker with existing low-level access to a computer could exploit improper file permissions to run malicious code with full administrative (SYSTEM) privileges. This could lead to a complete takeover of the affected system and loss of data integrity.
Technical details
A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in the installer for Sony Optical Disc Archive Software for Windows versions 5.5.3 and earlier. The flaw stems from improper file access permission settings established during installation. A local attacker with low-level privileges can exploit these weak permissions to replace or modify files, leading to arbitrary code execution with SYSTEM-level authority. Exploitation requires some user interaction and occurs under high-complexity conditions. Sony has addressed this issue in version 5.5.4.
Affected products
- Sony Optical Disc Archive Software 5.5.3 and earlier
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched: Fixed in version 5.5.4