logo

From Viewer to SYSTEM: Critical 10.0 CVSS Flaw in GeoVision ERM Allows Full Host Takeover

ID: 5439df72-76f9-549f-a11f-4d0c61684afa

STIX ID: report--5439df72-76f9-549f-a11f-4d0c61684afa

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

GeoVision disclosed a critical local privilege escalation vulnerability (CVE-2026-4606, CVSS v4 10.0) in GV-Edge Recording Manager (V2.3.1 and earlier) where processes are spawned under the Windows Local System account; functions that invoke Windows file dialogs can be abused by a low-privileged local user to access, modify, or delete protected system files, potentially resulting in full system compromise. GeoVision released a patch in V2.3.2 and administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.