Impact
A DLL hijacking flaw in the GeoVision GV‑IP Device Utility allows a local attacker to place a malicious DLL in a directory that the application scans before the legitimate library location. When the utility loads the library, the attacker’s code runs with the same privileges as the application, enabling arbitrary execution on the affected system. The weakness is cataloged as CWE‑427, reflecting the unsafe search order of dynamic‑link libraries.
Affected Systems
GeoVision Inc. manufactures the GV‑IP Device Utility for Windows. The vulnerability affects version 9.0.7.0; the vendor released 9.0.8.0 with the fix. All other recent releases are not listed as affected in the current data.
Risk and Exploitability
The CVSS score of 7.3 signals a high severity vulnerability, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild at present. This is a local attack vector: a user with the ability to write to the DLL search path can trigger the flaw, but it does not require network access or elevated privileges to discover or exploit. The vulnerability is not present in the CISA KEV catalog, yet the potential for arbitrary code execution warrants prompt remediation.
OpenCVE Enrichment