From Viewer to SYSTEM: Critical 10.0 CVSS Flaw in GeoVision ERM Allows Full Host Takeover
ID: 5439df72-76f9-549f-a11f-4d0c61684afa
STIX ID: report--5439df72-76f9-549f-a11f-4d0c61684afa
Feed Name: securityonline.info
GeoVision disclosed a critical local privilege escalation vulnerability (CVE-2026-4606, CVSS v4 10.0) in GV-Edge Recording Manager (V2.3.1 and earlier) where processes are spawned under the Windows Local System account; functions that invoke Windows file dialogs can be abused by a low-privileged local user to access, modify, or delete protected system files, potentially resulting in full system compromise. GeoVision released a patch in V2.3.2 and administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
