Unrated severityNVD Advisory· Published Nov 17, 2005· Updated Apr 16, 2026
CVE-2005-3650
CVE-2005-3650
Description
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.
Affected products
1- cpe:2.3:a:first4internet_xcp_drm:first4internet_xcp_drm:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/17610nvdVendor Advisory
- www.kb.cert.org/vuls/id/312073nvdThird Party AdvisoryUS Government Resource
- www.vupen.com/english/advisories/2005/2454nvdVendor Advisory
- hack.fi/~muzzy/sony-drm/nvd
- www.freedom-to-tinker.comnvd
- www.osvdb.org/20887nvd
- www.securityfocus.com/bid/15430nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/23063nvd
News mentions
0No linked articles in our index yet.