Fujitsu UpdateNavi Improper Communication Channel Restriction Vulnerability Allowing Registry Modification or Code Execution

Vulnerability

A vulnerability exists in Fujitsu UpdateNavi versions 1.4 L10 to L33 and the UpdateNaviInstallService Service versions 1.2.0091 to 1.2.0125. This vulnerability involves improper restriction of communication channels, allowing local authenticated attackers to send malicious data that could modify arbitrary registry values or execute arbitrary code.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of registry values or execution of arbitrary code on the affected system.

Remediation

Users can update to the latest version of UpdateNavi and the UpdateNaviInstallService. The application will automatically update when connected to the Internet. For manual update instructions, refer to the Fujitsu support website.

Added: Jun 12, 2025, 6:20 AM
Updated: Jun 12, 2025, 6:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.