CVE-2026-16519

Summary

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.

Affected Software

VendorProductVersion RangeStatus
GeoVision Inc.GV-IP Device Utility9.0.7.0affected
GeoVision Inc.GV-IP Device Utility9.0.8.0unaffected

Weaknesses

  • CWE-427: CWE-427: Uncontrolled Search Path Element (DLL Search Order Hijacking / DLL Side-Loading)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References