D-Link D-View 8 Installer DLL Preloading Vulnerability

Vulnerability

A DLL preloading vulnerability has been identified in the D-Link D-View 8 installer, specifically in versions through 2.0.1.107. This vulnerability arises from an uncontrolled search path element, allowing attackers to execute malicious code with administrative privileges. When the installer is run with elevated rights via User Account Control (UAC), it attempts to load a DLL file from its execution directory. An attacker can place a harmful version.dll file alongside the legitimate installer, so that when the installer is executed and the UAC prompt is approved, the malicious code is executed. This could lead to a complete system compromise.

Impact

Exploitation of this vulnerability allows for unauthorized code execution with administrative rights, potentially leading to full system compromise.

Remediation

Users are advised to update to D-View 8 version 2.0.5.109 Beta. This beta version can be downloaded from the D-Link D-View 8 Free Trial page. After updating, it is important to verify the success of the update by checking the firmware version on the product interface.

Added: Jan 21, 2026, 6:46 PM
Updated: Jan 21, 2026, 6:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.0
remediation
7.7
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.