A
DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility
desktop application. The application loads one or more dynamic-link libraries
(DLLs) from an unsafe search path, allowing a local attacker to place a
malicious DLL in a location searched before the legitimate library
location.
GeoVision GV-IP Device Utility Device version 9.0.8.0 has patched reported vulnerability.
User is recommended to update to version 9.0.8.0 from GeoVision's offical website
(https://www.geovision.com.tw/download/product/GV-VMS%20V20)
or contact GeoVision Support team