CVE-2026-32679 is a DLL hijacking vulnerability affecting the installers of LiveOn Meet Client for Windows and Canon Network Camera Plugin. The vulnerable installers (Downloader5Installer.exe, Downloader5InstallerForAdmin.exe, CanonNWCamPlugin.exe, and CanonNWCamPluginForAdmin.exe) insecurely load dynamic link libraries, allowing an attacker to place a malicious DLL in the same directory and achieve code execution with user privileges. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring no privileges but user interaction to trigger. Successful exploitation results in complete compromise of confidentiality, integrity, and availability on the affected system. The attack complexity is low, indicating it can be executed reliably. Currently, CVE-2026-32679 shows no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.00014 indicates minimal probability of exploitation relative to other CVEs, suggesting this remains a low-priority threat from an operational standpoint.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.0CPE matchmatch criteria | cpe:2.3:a:liveon:canonnwcamplugin.exe:1.0.0.0:*:*:*:*:windows:*:* | ||
1.0.0.0CPE matchmatch criteria | cpe:2.3:a:liveon:canonnwcampluginforadmin.exe:1.0.0.0:*:*:*:*:windows:*:* | ||
1.0.0.0CPE matchmatch criteria | cpe:2.3:a:liveon:downloader5installer.exe:1.0.0.0:*:*:*:*:windows:*:* | ||
1.0.0.0CPE matchmatch criteria | cpe:2.3:a:liveon:downloader5installerforadmin.exe:1.0.0.0:*:*:*:*:windows:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.