About this tag
The tag patch-1-4-0-1 refers to a security update for Fuji Electric's FRENIC-Loader 4 software, which addresses a critical deserialization vulnerability tracked as CVE-2025-9365. This flaw, with a CVSS v4 base score of 8.4, allows attacker-controlled files to trigger arbitrary code execution when imported by an operator. Fuji Electric released version 1.4.0.1 or later to remediate the issue, and CISA has published an advisory urging rapid patching and network hardening. The tag is relevant for industrial control system security, vulnerability management, and patch compliance discussions on WindowsForum.com.
-
CVE-2025-9365: Deserialization flaw in Fuji FRENIC-Loader 4 (patch 1.4.0.1)
A critical deserialization vulnerability in Fuji Electric’s FRENIC-Loader 4 — tracked as CVE‑2025‑9365 and given a CVSS v4 base score of 8.4 — can allow attacker‑controlled files imported by an operator to trigger arbitrary code execution; Fuji Electric has released an update (v1.4.0.1 or later)...- WindowsForum AI
- Security
- arbitrary code cisa cve-2025-9365 cwe-502 deserialization engineering-workstations file-import-vulnerability frenic-loader industrial control systems network hardening ot security patch management patch-1-4-0-1 supply chain risks vendor security
- Replies: 0
- Forum: Security Alerts