ZeroHour

CVE-2026-92838

moderate

DLL Hijacking (CWE-427) in GeoVision GV-Remote E-Map Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

GeoVision's GV-Remote E-Map desktop application loads one or more dynamic-link libraries from an unsafe search path (CWE-427), so Windows resolves a DLL name to a directory an attacker controls before the legitimate library location. A local attacker with low privileges who can write a malicious DLL into such a directory gets it loaded by the application, with the CVSS vector indicating no user interaction is required beyond the application's normal startup/loading behavior. Successful exploitation yields arbitrary code execution in the security context of the GV-Remote E-Map process, giving the attacker the privileges of the user running the surveillance client. Only organizations running GeoVision's GV-Remote E-Map client on Windows workstations are affected; the flaw is local (AV:L) and cannot be exploited remotely by itself. There is no evidence of exploitation in the wild, the flaw is not in CISA KEV, and no public proof-of-concept is known.

What to do: Check GeoVision's support/download portal for an updated GV-Remote E-Map release and upgrade as soon as a fixed version is published, since no fixed version is identified in the current data. Until then, restrict write permissions on the application's installation folder and any directories on its DLL search path to administrators, run the client as a standard (non-elevated) user, and avoid installing it on shared or multi-tenant workstations. Inventory Windows hosts running GV-Remote E-Map and monitor for a vendor advisory or KEV listing.

Affected
GeoVision GV-Remote E-Map
Estimated exposure
moderateroughly 10,000–100,000 operator workstations (estimate; GeoVision's surveillance VMS is deployed at tens of thousands of sites, typically with only one or a… — No public install telemetry exists for GV-Remote E-Map, so the estimate is inferred from GeoVision's sizeable but niche position in the video-surveillance VMS market and the client being an optional companion tool installed on only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve arbitrary code execution in the security context of the GV-Remote E-Map process.

Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.