CVE-2026-92838: GeoVision GV-Remote E-Map dll hijacking vulnerability
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve arbitrary code execution in the security context of the GV-Remote E-Map process.
Affected Software
Event History
Frequently Asked Questions
Can this be exploited remotely or without prior access?
No. The attack vector is local, and the attacker needs low-level privileges plus write access to a directory searched by the application for DLLs. No user interaction is required.
What access would successful exploitation provide?
A successful attacker could execute arbitrary code in the security context of the GV-Remote E-Map process. The reported impact includes high confidentiality, integrity, and availability impact.
Does exploitation affect a different security authority or scope?
No. The reported CVSS scope is unchanged, meaning the reported impact is within the security authority of the vulnerable GV-Remote E-Map process.