漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege
Vulnerability Description
GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. During installation, ERM creates a Windows service that runs under the LocalSystem account. When the ERM application is launched, related processes are spawned under SYSTEM privileges rather than the security context of the logged-in user. Functions such as 'Import Data' open a Windows file dialog operating with SYSTEM permissions, enabling modification or deletion of protected system files and directories. Any ERM function invoking Windows file open/save dialogs exposes the same risk. This vulnerability allows local privilege escalation and may result in full system compromise.
CVSS Information
N/A
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
GeoVision GV Edge Recording Manager 安全漏洞
Vulnerability Description
GeoVision GV Edge Recording Manager是中国GeoVision公司的一个用于管理和监控视频录制设备的软件。 GeoVision GV Edge Recording Manager 2.3.1版本存在安全漏洞,该漏洞源于以SYSTEM权限运行应用组件,可能导致本地权限提升和系统完全被控制。
CVSS Information
N/A
Vulnerability Type
N/A