{"api_version":"1","generated_at":"2026-07-23T08:46:48+00:00","cve":"CVE-2005-3650","urls":{"html":"https://cve.report/CVE-2005-3650","api":"https://cve.report/api/cve/CVE-2005-3650.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3650","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3650"},"summary":{"title":"CVE-2005-3650","description":"The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has \"safe for scripting\" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-17 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/312073","name":"http://www.kb.cert.org/vuls/id/312073","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#312073","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/20887","name":"http://www.osvdb.org/20887","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15430","name":"http://www.securityfocus.com/bid/15430","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"First 4 Internet CodeSupport Uninstallation ActiveX Software Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://hack.fi/~muzzy/sony-drm/","name":"http://hack.fi/~muzzy/sony-drm/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sony's XCP DRM","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17610","name":"http://secunia.com/advisories/17610","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Sony CD First4Internet XCP Uninstallation ActiveX Control Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.freedom-to-tinker.com/?p=927","name":"http://www.freedom-to-tinker.com/?p=927","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Freedom to Tinker  » Blog Archive   » Sony’s Web-Based Uninstaller Opens a Big Security Hole; Sony to Recall Discs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2454","name":"http://www.vupen.com/english/advisories/2005/2454","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23063","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23063","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3650","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3650","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3650","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"first4internet_xcp_drm","cpe5":"first4internet_xcp_drm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:17:23.426Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17610","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17610"},{"name":"ADV-2005-2454","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2454"},{"name":"20887","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/20887"},{"name":"VU#312073","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/312073"},{"name":"15430","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15430"},{"name":"first4internet-xcp-sony-gain-access(23063)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23063"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.freedom-to-tinker.com/?p=927"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://hack.fi/~muzzy/sony-drm/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has \"safe for scripting\" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17610","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17610"},{"name":"ADV-2005-2454","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2454"},{"name":"20887","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/20887"},{"name":"VU#312073","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/312073"},{"name":"15430","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15430"},{"name":"first4internet-xcp-sony-gain-access(23063)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23063"},{"tags":["x_refsource_MISC"],"url":"http://www.freedom-to-tinker.com/?p=927"},{"tags":["x_refsource_MISC"],"url":"http://hack.fi/~muzzy/sony-drm/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3650","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has \"safe for scripting\" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17610","refsource":"SECUNIA","url":"http://secunia.com/advisories/17610"},{"name":"ADV-2005-2454","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2454"},{"name":"20887","refsource":"OSVDB","url":"http://www.osvdb.org/20887"},{"name":"VU#312073","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/312073"},{"name":"15430","refsource":"BID","url":"http://www.securityfocus.com/bid/15430"},{"name":"first4internet-xcp-sony-gain-access(23063)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23063"},{"name":"http://www.freedom-to-tinker.com/?p=927","refsource":"MISC","url":"http://www.freedom-to-tinker.com/?p=927"},{"name":"http://hack.fi/~muzzy/sony-drm/","refsource":"MISC","url":"http://hack.fi/~muzzy/sony-drm/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3650","datePublished":"2005-11-17T11:00:00.000Z","dateReserved":"2005-11-17T00:00:00.000Z","dateUpdated":"2024-08-07T23:17:23.426Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-17 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:first4internet_xcp_drm:first4internet_xcp_drm:*:*:*:*:*:*:*:*","matchCriteriaId":"38F63CDF-09CA-4D7F-893F-44D196A032C1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3650","Ordinal":"1","Title":"CVE-2005-3650","CVE":"CVE-2005-3650","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3650","Ordinal":"1","NoteData":"The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has \"safe for scripting\" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.","Type":"Description","Title":"CVE-2005-3650"},{"CveYear":"2005","CveId":"3650","Ordinal":"2","NoteData":"2005-11-17","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3650","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}