PT-2026-27040 · Unknown · Gv-Edge Recording Manager

CVE-2026-4606

·

Published

2026-03-23

·

Updated

2026-03-25

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:N/R:I/V:C/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions GV Edge Recording Manager version 2.3.1
Description The software improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. The software creates a Windows service that runs under the LocalSystem account, and related processes are spawned under SYSTEM privileges instead of the logged-in user's security context. Functions like 'Import Data' open Windows file dialogs with SYSTEM permissions, potentially enabling modification or deletion of protected system files and directories. Any function invoking Windows file open/save dialogs exposes the same risk, leading to local privilege escalation and potential full system compromise.
Recommendations Versions prior to 2.3.1 are recommended.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4606

Affected Products

Gv-Edge Recording Manager