CVE-2026-92838
moderateDLL Hijacking (CWE-427) in GeoVision GV-Remote E-Map Enables Local Code Execution
GeoVision's GV-Remote E-Map desktop application loads one or more dynamic-link libraries from an unsafe search path (CWE-427), so Windows resolves a DLL name to a directory an attacker controls before the legitimate library location. A local attacker with low privileges who can write a malicious DLL into such a directory gets it loaded by the application, with the CVSS vector indicating no user interaction is required beyond the application's normal startup/loading behavior. Successful exploitation yields arbitrary code execution in the security context of the GV-Remote E-Map process, giving the attacker the privileges of the user running the surveillance client. Only organizations running GeoVision's GV-Remote E-Map client on Windows workstations are affected; the flaw is local (AV:L) and cannot be exploited remotely by itself. There is no evidence of exploitation in the wild, the flaw is not in CISA KEV, and no public proof-of-concept is known.
What to do: Check GeoVision's support/download portal for an updated GV-Remote E-Map release and upgrade as soon as a fixed version is published, since no fixed version is identified in the current data. Until then, restrict write permissions on the application's installation folder and any directories on its DLL search path to administrators, run the client as a standard (non-elevated) user, and avoid installing it on shared or multi-tenant workstations. Inventory Windows hosts running GV-Remote E-Map and monitor for a vendor advisory or KEV listing.
| GeoVision GV-Remote E-Map | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve arbitrary code execution in the security context of the GV-Remote E-Map process.
- Weakness
- CWE-427
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.