Description

GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.  During installation, ERM creates a Windows service that runs under the LocalSystem account.  When the ERM application is launched, related processes are spawned under SYSTEM privileges rather than the security context of the logged-in user.  Functions such as 'Import Data' open a Windows file dialog operating with SYSTEM permissions, enabling modification or deletion of protected system files and directories.  Any ERM function invoking Windows file open/save dialogs exposes the same risk.  This vulnerability allows local privilege escalation and may result in full system compromise.

INFO

Published Date :

2026-03-23T01:05:31.952Z

Last Modified :

2026-03-24T03:56:02.798Z

Source :

GV
AFFECTED PRODUCTS

The following products are affected by CVE-2026-4606 vulnerability.

Vendors Products
Geovision
  • Gv-edge Recording Manager
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4606.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability