CVE-2026-18755: GV-ASManager DLL hijacking vulnerability
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed under the security privileges of the GV-ASManager process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18755?
The severity of CVE-2026-18755 is rated high with a score of 7.3.
What is CVE-2026-18755?
CVE-2026-18755 describes a DLL hijacking vulnerability in GeoVision GV-ASManager that allows a local attacker to execute arbitrary code.
How do I fix CVE-2026-18755?
To fix CVE-2026-18755, ensure that access permissions to the application’s search directories are properly restricted and monitor for any unauthorized changes.
Who is affected by CVE-2026-18755?
Users and administrators of GeoVision GV-ASManager who grant write access to unsafe search directories are affected by CVE-2026-18755.
What types of attacks are possible with CVE-2026-18755?
CVE-2026-18755 allows a local attacker to place a crafted DLL in the application search path to execute malicious code.