PT-2025-25282 · Unknown · Updatenavi+1

Shu Yoshikoshi

·

Published

2025-06-12

·

Updated

2025-06-12

·

CVE-2025-35978

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions UpdateNavi versions 1.4 L10 through 1.4 L33 UpdateNaviInstallService Service versions 1.2.0091 through 1.2.0125
Description The issue exists due to improper restriction of communication channel to intended endpoints. If a local authenticated attacker sends malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
Recommendations For UpdateNavi versions 1.4 L10 through 1.4 L33, consider restricting access to the communication channel to prevent malicious data from being sent. For UpdateNaviInstallService Service versions 1.2.0091 through 1.2.0125, consider implementing proper restrictions on the communication channel to intended endpoints to prevent arbitrary registry value modification or code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-35978

Affected Products

Updatenavi
Updatenaviinstallservice Service