Vulnerability Description
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://azby.fmworld.net/support/security/information/updatenavi202506/
- https://jvn.jp/en/jp/JVN17860456/
FAQ
What is CVE-2025-35978?
CVE-2025-35978 is a vulnerability with a CVSS score of 7.1 (HIGH). Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attac...
How severe is CVE-2025-35978?
CVE-2025-35978 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-35978?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.