CVE Database
/

CVE-2025-35978

Back to search

CVE-2025-35978

Published: Jun 12, 2025

Modified: Jun 12, 2025

PUBLISHED

CVSS v3.0

7.1

HIGH

Description

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.

VendorProductVersions

Fujitsu Client Computing Limited

UpdateNavi

affected
V1.4 L10 to L33

Fujitsu Client Computing Limited

UpdateNaviInstallService

affected
Service 1.2.0091 to 1.2.0125

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now