CVE-2026-68955
largeDLL Hijacking in Rakuten Kobo Desktop Application Installer (Windows)
The Windows installer for the Rakuten Kobo Desktop Application contains an uncontrolled search path flaw (CWE-427) that causes it to insecurely load dynamic link libraries. If an attacker is able to place a crafted DLL in the same directory as the installer — for example, a user's Downloads folder — and the user then runs the installer, the malicious DLL is loaded and arbitrary code executes with the privileges of the user performing the installation. Exploitation requires local access to plant the file plus user interaction to launch the installer, which matches the CVSS 4.0 local vector (8.4, high). Anyone who downloads and runs the Kobo Desktop installer on Windows is potentially exposed, particularly on shared machines or where files arrive from untrusted sources into the same folder. No public proof of concept is known, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Download the Kobo Desktop installer only from Kobo's official website and never run it from email attachments, network shares, or other untrusted locations. Before launching, inspect the installer's folder (e.g., Downloads) for unexpected .dll files and remove them, and perform installs from a standard non-administrator account so any hijacked code has limited privileges. Defenders should monitor for the Kobo installer process loading DLLs from user-writable directories, and check JPCERT/vendor advisories for a fixed installer version, as no patched version range has been published in the current data.
| Rakuten Kobo Kobo Desktop Application (Windows version) installer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
- Weakness
- CWE-427
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.