CVE-2026-23755

CWE-4273 documents3 sources
Severity
8.4HIGH
EPSS
0.0%
top 96.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21

Description

D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full s

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDdlink/d-view_82.0.1.107
CVEListV5d-link/d-view_82.0.1.107

Patches

🔴Vulnerability Details

2
CVEList
D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path2026-01-21
GHSA
GHSA-52pj-q5jq-xr5g: D-Link D-View 8 versions 22026-01-21
CVE-2026-23755 (HIGH CVSS 8.4) | D-Link D-View 8 versions 2.0.1.107 | cvebase.io