CVE-2026-16519: GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-IP Device Utilityto a version that resolves this vulnerability.Fixed in 9.0.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16519?
The severity of CVE-2026-16519 is rated high with a score of 7.3.
How do I fix CVE-2026-16519?
To fix CVE-2026-16519, ensure that the GeoVision GV-IP Device Utility application is updated to the latest version that addresses this DLL hijacking vulnerability.
What types of attacks are possible with CVE-2026-16519?
With CVE-2026-16519, a local attacker can exploit the vulnerability to execute malicious code by placing a harmful DLL in the search path before the legitimate DLL.
Which software is affected by CVE-2026-16519?
The vulnerability affects the GeoVision GV-IP Device Utility desktop application.
When was CVE-2026-16519 published?
CVE-2026-16519 was published on July 24, 2026.