CVE-2025-35978 Information

Description

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data an arbitrary registry value may be modified or arbitrary code may be executed.

Reference

https://azby.fmworld.net/support/security/information/updatenavi202506/ https://jvn.jp/en/jp/JVN17860456/

CNNVD-202506-1649 (Published: 2025-06-12)

Share on: