Impact
A DLL hijacking flaw in GeoVision GV-ASManager permits a local attacker who can write to an unsafe search directory to substitute a malicious library. If the attacker places a crafted DLL before the legitimate one, the vulnerable process loads and runs the attacker’s code with the same privileges as GV-ASManager. The flaw is a classic example of the CWE‑428 weakness, allowing compromise of confidentiality, integrity, and availability in the affected system.
Affected Systems
The vulnerability affects the GeoVision GV-ASManager application. No specific product version is identified in the current data, so any installation that includes the application’s loading mechanism is potentially susceptible.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity local vulnerability; the EPSS score is unknown and the flaw is not listed in the CISA KEV catalog. A local attacker with write access to the application’s search directory can exploit the issue directly, enabling execution of arbitrary code under the GV-ASManager process context. The attack requires only local access and permission to place a DLL in the unsafe directory, making it a practical threat for insiders or privileged users.
OpenCVE Enrichment