PT-2025-25282 · Unknown · Updatenavi+1
Shu Yoshikoshi
·
Published
2025-06-12
·
Updated
2025-06-12
·
CVE-2025-35978
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UpdateNavi versions 1.4 L10 through 1.4 L33
UpdateNaviInstallService Service versions 1.2.0091 through 1.2.0125
Description
The issue exists due to improper restriction of communication channel to intended endpoints. If a local authenticated attacker sends malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
Recommendations
For UpdateNavi versions 1.4 L10 through 1.4 L33, consider restricting access to the communication channel to prevent malicious data from being sent.
For UpdateNaviInstallService Service versions 1.2.0091 through 1.2.0125, consider implementing proper restrictions on the communication channel to intended endpoints to prevent arbitrary registry value modification or code execution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Updatenavi
Updatenaviinstallservice Service