CVE-2026-4606 Details
Description
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. During installation, ERM creates a Windows service that runs under the LocalSystem account. When the ERM application is launched, related processes are spawned under SYSTEM privileges rather than the security context of the logged-in user. Functions such as 'Import Data' open a Windows file dialog operating with SYSTEM permissions, enabling modification or deletion of protected system files and directories. Any ERM function invoking Windows file open/save dialogs exposes the same risk. This vulnerability allows local privilege escalation and may result in full system compromise.
A local privilege escalation vulnerability has been identified in GeoVision GV Edge Recording Manager (ERM) version 2.3.1. The issue arises because the application improperly executes components with SYSTEM-level privileges. This flaw enables any local user to gain complete control over the operating system. During installation, ERM establishes a Windows service that operates under the LocalSystem account. Consequently, when the application is launched, associated processes inherit SYSTEM privileges instead of the security context of the logged-in user. Features like 'Import Data' trigger a Windows file dialog that operates with SYSTEM permissions, potentially allowing users to modify or delete protected system files and directories. This risk extends to any ERM function that invokes Windows file open or save dialogs. The vulnerability could lead to a full system compromise.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 23, 2026CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://https://www.geovision.com.tw/cyber_security.php | GV |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | GV |
Affected Products
| Product | Versions |
|---|---|
| GV Edge Recording Manager | 2.3.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | GV |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 23, 2026 | New CVE Received | GV |
Volerion