Impact
A DLL hijacking vulnerability in GeoVision GV-Remote E-Map allows an attacker with local write access to a monitored directory to place a malicious DLL that the application will load before the legitimate one. If the hijack succeeds, the attacker can execute arbitrary code within the security context of the GV-Remote E-Map process, potentially compromising sensitive data or enabling further lateral movement within the host. The weakness originates from the application loading libraries from an unsafe search path, a classic example of path traversal in DLL resolution.
Affected Systems
Affected products include GeoVision Inc.'s GV-Remote E-Map desktop application, specifically versions 18.3.1 and 18.4 for Windows. No additional vendors or product lines are listed, and the known Common Platform Enumeration identifiers confirm these two affected releases. Users running these versions should check for a vendor-provided update or consider downgrading to a secure baseline if a patch is not yet available.
Risk and Exploitability
The CVSS score of 7.8 reflects significant potential impact, while the EPSS score of < 1% indicates a low current likelihood of public exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale exploits. Exploitation requires local file‑system write permission in a location searched by the application and may be mitigated by restricting access or applying an official fix. The attack vector is local and relies on user‑level privileges, but the resultant code execution occurs with the application's privileges, which may be elevated.
OpenCVE Enrichment