A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed under the security privileges of the GV-ASManager process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-18755 is a DLL hijacking vulnerability affecting GeoVision's GV-ASManager application, where an attacker with local write access can place a malicious DLL in the application's search path to achieve arbitrary code execution. This vulnerability matters because it exploits a fundamental weakness in how Windows resolves library dependencies—allowing attackers to intercept legitimate function calls and execute their own code with the privileges of the vulnerable application. Organizations using GeoVision surveillance and access management systems are at risk, particularly in environments where local attackers or compromised user accounts have write access to directories in the application's search path.
While this CVE doesn't map directly to MITRE ATT&CK techniques in the official framework, Casky's 754 security skills would detect the attack patterns associated with Execution, Persistence, and Privilege Escalation through behavioral analysis of DLL loading sequences and file system modifications. Practitioners using Casky would see findings related to suspicious DLL placement in unsafe directories, anomalous library load orders, and process execution with unexpected privilege levels. Although currently unmapped to specific techniques, the detection would flag indicators such as unsigned DLLs in application directories, write access patterns to system paths, and privilege escalation attempts following DLL injection—enabling security teams to identify and remediate this class of vulnerability before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-18755. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation