CVE-2025-35978: Fujitsu Client Computing Limited Updatenavi
Medium severity, CVSS 6.9. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
Affected products
- Fujitsu Client Computing Limited Updatenavi
- Fujitsu Client Computing Limited Updatenaviinstallservice
Published 2025-06-12. Last modified 2026-06-17.