PT-2026-27040 · Unknown · Gv-Edge Recording Manager
Published
2026-03-23
·
Updated
2026-03-25
·
CVE-2026-4606
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:N/R:I/V:C/RE:M/U:Green |
Name of the Vulnerable Software and Affected Versions
GV Edge Recording Manager version 2.3.1
Description
The software improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system. The software creates a Windows service that runs under the LocalSystem account, and related processes are spawned under SYSTEM privileges instead of the logged-in user's security context. Functions like 'Import Data' open Windows file dialogs with SYSTEM permissions, potentially enabling modification or deletion of protected system files and directories. Any function invoking Windows file open/save dialogs exposes the same risk, leading to local privilege escalation and potential full system compromise.
Recommendations
Versions prior to 2.3.1 are recommended.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-Edge Recording Manager