CVE-2026-18755

Summary

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed under the security privileges of the GV-ASManager process.

Affected Software

VendorProductVersion RangeStatus
GeoVision Inc.GV-ASManagerV6.3.0affected
GeoVision Inc.GV-ASManagerV6.4.0unaffected

Weaknesses

  • CWE-428: CWE-428 Unquoted search path or element

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References