Published:2026/06/16 Last Updated:2026/06/16
JVN#79926428
Improper file access permission settings in the installers for Optical Disc Archive Software for Windows
Overview
Optical Disc Archive Software for Windows provided by Sony Corporation is configured with improper file access permission settings.
Products Affected
- Optical Disc Archive Software for Windows 5.5.3 and earlier
Description
Optical Disc Archive Software for Windows provided by Sony Corporation contains the following vulnerability.
- Incorrect default permissions (CWE-276)
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
- CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
- CVE-2026-50255
Impact
Arbitrary code may be executed with SYSTEM privileges.
Solution
Use the latest installer
Use the latest installer provided by the developer.
For more details, refer to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Sony Corporation | Software: Optical Disc Archive Software(Driver) V5.5.4 (Windows) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-50255 |
| JVN iPedia |
JVNDB-2026-000084 |