Fujitsu UpdateNavi Improper Communication Channel Restriction Vulnerability Allowing Registry Modification or Code Execution
Vulnerability
A vulnerability exists in Fujitsu UpdateNavi versions 1.4 L10 to L33 and the UpdateNaviInstallService Service versions 1.2.0091 to 1.2.0125. This vulnerability involves improper restriction of communication channels, allowing local authenticated attackers to send malicious data that could modify arbitrary registry values or execute arbitrary code.
Impact
Exploitation of this vulnerability could lead to unauthorized modification of registry values or execution of arbitrary code on the affected system.
Remediation
Users can update to the latest version of UpdateNavi and the UpdateNaviInstallService. The application will automatically update when connected to the Internet. For manual update instructions, refer to the Fujitsu support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
