CVE-2026-23755: D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path
D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23755?
CVE-2026-23755 is classified as a high severity vulnerability due to its potential impact when exploited with elevated privileges.
How do I fix CVE-2026-23755?
To fix CVE-2026-23755, upgrade to D-Link D-View 8 version 2.0.1.108 or later, which mitigates the uncontrolled search path vulnerability.
What systems are affected by CVE-2026-23755?
CVE-2026-23755 affects D-Link D-View 8 versions 2.0.1.107 and earlier.
What is the nature of CVE-2026-23755?
CVE-2026-23755 is a DLL preloading vulnerability that allows an attacker to execute malicious code with elevated privileges.
Is there a workaround for CVE-2026-23755?
There are no documented workarounds for CVE-2026-23755; updating the software is the recommended course of action.