CVE-2025-64772 Details
Description
The installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.
A vulnerability exists in the installer of Sony INZONE Hub versions 1.0.10.3 through 1.0.17.0, due to an improper DLL search path. This flaw may allow the installer to insecurely load Dynamic Link Libraries, potentially leading to arbitrary code execution with the privileges of the user running the installer.
Users are advised to update to the latest version of the INZONE Hub installer, version 1.0.17.1, released on November 27, 2025.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 1, 2025CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN28247549/ | [email protected] | AdvisoryRemedy |
| https://www.sony.com/electronics/support/others-software/inzone-hub | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Sony INZONE Hub | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | New CVE Received | [email protected] |
Volerion