Junglewise Threat Intelligence

CVE-2026-16519: GeoVision GV-IP Device Utility DLL hijacking

CVE-2026-16519 · Severity: high · CVSS 7.3 · Published 2026-07-24

Technologies: Geovision GV-IP Device Utility. Vendors: Geovision.

Executive brief

A security vulnerability exists in the GeoVision GV-IP Device Utility, a desktop application used to manage and configure GeoVision IP cameras and surveillance devices. A local attacker can trick the application into running malicious code by placing a specially crafted file in a specific folder on the computer. If successful, this could allow the attacker to gain full control over the system, potentially leading to data theft or disruption of the surveillance network.

Technical details

A DLL hijacking vulnerability (CWE-427: Uncontrolled Search Path Element) exists in the GeoVision GV-IP Device Utility version 9.0.7.0. The application attempts to load one or more dynamic-link libraries (DLLs) using an unsafe search path. A local attacker with low privileges can exploit this by placing a malicious DLL in a directory that is searched before the legitimate system or application directories. Execution occurs when a user launches the application, leading to arbitrary code execution with the privileges of the application user. GeoVision has released version 9.0.8.0 to address this issue.

Affected products

  • GeoVision Inc. GV-IP Device Utility 9.0.7.0

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory
  • 2026-07-24: patched: Fixed in version 9.0.8.0

References

Related threats