DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility
desktop application. The application loads one or more dynamic-link libraries
(DLLs) from an unsafe search path, allowing a local attacker to place a
malicious DLL in a location searched before the legitimate library
location.
No analysis available yet.
Vendor Solution
GeoVision GV-IP Device Utility Device version 9.0.8.0 has patched reported vulnerability. User is recommended to update to version 9.0.8.0 from GeoVision's offical website (https://www.geovision.com.tw/download/product/GV-VMS%20V20) or contact GeoVision Support team
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.geovision.com.tw/cyber_security.php |
|
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geovision
Geovision gv-ip Device Utility |
|
| Vendors & Products |
Geovision
Geovision gv-ip Device Utility |
|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. | |
| Title | GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability | |
| First Time appeared |
Geovision Inc.
Geovision Inc. gv-ip Device Utility |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:geovision_inc.:gv-ip_device_utility:9.0.7.0:*:windows:*:*:*:*:* cpe:2.3:a:geovision_inc.:gv-ip_device_utility:9.0.8.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Geovision Inc.
Geovision Inc. gv-ip Device Utility |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GV
Published:
Updated: 2026-07-24T12:29:41.082Z
Reserved: 2026-07-22T00:55:03.834Z
Link: CVE-2026-16519
Updated: 2026-07-24T12:29:37.819Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T10:15:02Z
-
CWE-427
Uncontrolled Search Path Element