CVE-2025-35978

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
Configurations

No configuration.

History

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Existe un problema de restricción incorrecta del canal de comunicación a los endpoints previstos en UpdateNavi V1.4 L10 a L33 y UpdateNaviInstallService Service 1.2.0091 a 1.2.0125. Si un atacante local autenticado envía datos maliciosos, se podría modificar un valor de registro arbitrario o ejecutar código arbitrario.

12 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 06:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-35978

Mitre link : CVE-2025-35978

CVE.ORG link : CVE-2025-35978


JSON object : View

Products Affected

No product.

CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints