Description
A DLL hijacking
vulnerability exists in the GeoVision GV-Remote E-Map desktop
application. The application loads one or more dynamic-link libraries (DLLs)
from an unsafe search path, allowing a local attacker to place a malicious DLL
in a location searched before the legitimate library location. If
successfully exploited, an attacker with local write access to the affected
directory could achieve arbitrary code execution in the security context of
the GV-Remote E-Map process.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Arbitrary Code Execution via DLL Hijacking
Action: Immediate Patch
AI Analysis

Impact

A DLL hijacking vulnerability in GeoVision GV-Remote E-Map allows an attacker with local write access to a monitored directory to place a malicious DLL that the application will load before the legitimate one. If the hijack succeeds, the attacker can execute arbitrary code within the security context of the GV-Remote E-Map process, potentially compromising sensitive data or enabling further lateral movement within the host. The weakness originates from the application loading libraries from an unsafe search path, a classic example of path traversal in DLL resolution.

Affected Systems

Affected products include GeoVision Inc.'s GV-Remote E-Map desktop application, specifically versions 18.3.1 and 18.4 for Windows. No additional vendors or product lines are listed, and the known Common Platform Enumeration identifiers confirm these two affected releases. Users running these versions should check for a vendor-provided update or consider downgrading to a secure baseline if a patch is not yet available.

Risk and Exploitability

The CVSS score of 7.8 reflects significant potential impact, while the EPSS score of < 1% indicates a low current likelihood of public exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale exploits. Exploitation requires local file‑system write permission in a location searched by the application and may be mitigated by restricting access or applying an official fix. The attack vector is local and relies on user‑level privileges, but the resultant code execution occurs with the application's privileges, which may be elevated.

Generated by OpenCVE AI on September 18, 2026 at 00:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest GeoVision GV-Remote E-Map patch that addresses DLL search order or upgrade to the most recent release that fixes the DLL hijacking flaw.
  • Modify the permissions on directories that the application scans for DLLs to remove write access for non‑privileged users, thereby preventing malicious DLL placement.
  • Configure or run the application with the principle of least privilege, ensuring that even if a DLL is hijacked it will execute under a restricted user account; consider placing the application in a protected folder and using Windows File System Control to lock DLL directories.

Generated by OpenCVE AI on September 18, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve arbitrary code execution in the security context of the GV-Remote E-Map process.
Title GeoVision GV-Remote E-Map dll hijacking vulnerability
First Time appeared Geovision Inc.
Geovision Inc. gv-remote E-map
Weaknesses CWE-427
CPEs cpe:2.3:a:geovision_inc.:gv-remote_e-map:v18.3.1:*:windows:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-remote_e-map:v18.4:*:windows:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-remote E-map
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-remote E-map
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-17T13:01:41.696Z

Reserved: 2026-09-17T00:39:13.604Z

Link: CVE-2026-92838

cve-icon Vulnrichment

Updated: 2026-09-17T13:01:35.318Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T02:16:28.610

Modified: 2026-09-18T19:41:42.593

Link: CVE-2026-92838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element