Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed. | |
| Weaknesses | CWE-923 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-06-12T06:05:00.260Z
Updated: 2025-06-12T13:04:50.949Z
Reserved: 2025-06-10T01:46:07.308Z
Link: CVE-2025-35978
Updated: 2025-06-12T13:04:48.345Z
Status : Awaiting Analysis
Published: 2025-06-12T06:15:23.207
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-35978
No data.