rootpwn

high · CVSS v3 7.8

CVE-2026-92838

A DLL hijacking flaw in GeoVision GV-Remote E-Map allows a local user with write access to a directory to drop a malicious DLL that is loade

Overview

A DLL hijacking flaw in GeoVision GV-Remote E-Map allows a local user with write access to a directory to drop a malicious DLL that is loaded before the legitimate one. If exploited, the attacker can run arbitrary code in the context of the GV-Remote E-Map process, potentially compromising local data and system integrity.

Description

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve arbitrary code execution in the security context of the GV-Remote E-Map process.

Impact

Local attackers who can write to the application directory can execute arbitrary code with the same privileges as the GV-Remote E-Map process, enabling data theft, modification, or service disruption on the affected machine.

Remediation

['Apply the vendor’s security patch or upgrade to the latest GV-Remote E-Map release.', 'Restrict write permissions on the application installation and data directories to administrators only.', 'Configure the system to use secure DLL search paths or enforce application whitelisting.', 'Verify DLL integrity with code signing or hash checks where possible.']

Risk context

The vulnerability is rated high (CVSS 7.8) and can lead to local code execution. Prompt patching is recommended to mitigate the risk of privilege escalation and data compromise.

Affected products

  • GeoVision GV-Remote E-Map
  • GeoVision

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.8
CVSS v4
EPSS

DLL hijacking local privilege code execution GeoVision GV-Remote E-Map high severity patch

← All CVEs