Impact
GV Edge Recording Manager v2.3.1 contains an improper privilege assignment flaw that causes the application to run components with SYSTEM-level privileges. During installation the software creates a Windows service that operates under the LocalSystem account, and subsequent ERM processes inherit this high privilege context. Because functions such as 'Import Data' use Windows file dialogs that also run under SYSTEM, any local user can manipulate protected system files, directories, or configurations. This flaw results in local privilege escalation, enabling an attacker to gain full control of the operating system.
Affected Systems
The vulnerability is specific to GeoVision's GV-Edge Recording Manager version 2.3.1. No other versions or GeoVision products are mentioned, and the CNA vendor list indicates only GV-Edge Recording Manager as affected. The risk applies to Windows environments where the ERM is installed and a local user has access to launch the application.
Risk and Exploitability
The CVSS score of 10.0 reflects a maximum severity and indicates that the vulnerability is exploitable in a local context with the attacker already having a user account. While EPSS data is not provided, the lack of a KEV listing does not diminish the need for timely remediation. An attacker can trigger the flaw by simply launching the ERM and selecting any function that opens a file dialog, thereby triggering SYSTEM‑level code execution. Once SYSTEM privileges are achieved, the attacker can compromise the entire host.
OpenCVE Enrichment