Post

Installer for Rakuten Kobo Desktop Application Vulnerability

Installer for Rakuten Kobo Desktop Application Vulnerability

Vulnerability Alert 🚨

Title: Installer for Rakuten Kobo Desktop Application (Windows version) may insecurely load Dynamic Link Libraries

Source: Japan Vulnerability Network

Date Published: August 27, 2026

Overview

JVN#18593874 reports a vulnerability where the installer for the Rakuten Kobo Desktop Application (Windows version) may insecurely load Dynamic Link Libraries. This issue affects the installer provided by Rakuten Kobo Inc., which may lead to the insecure loading of DLLs.

Affected Products

  • Installer for Rakuten Kobo Desktop Application (Windows version) distributed before July 15, 2026.

Vulnerability Details

The vulnerability is due to an insecure loading of Dynamic Link Libraries caused by a flaw in the DLL search path (CWE-427). It is identified as CVE-2026-68955 with a CVSS:4.0 Base Score of 8.4 and a CVSS:3.0 Base Score of 7.8.

Impact

If a crafted DLL exists in the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation. This issue is also discussed in Japan Vulnerability Notes JVNTA#91240916, which covers Insecure DLL Loading and Command Execution Issues on many Windows applications.

Solution

Users should utilize the latest installer provided by the developer. It is crucial to note that this vulnerability can only be exploited when the installer is invoked. If the product has already been installed, reinstallation is not necessary.

For further information, visit the developer’s website.

Reporting

This vulnerability was reported by Yukihiro Nakamura to IPA, with JPCERT/CC coordinating with the developer under the Information Security Early Warning Partnership.

For more details, see the complete article: Read full article

This post is licensed under CC BY 4.0 by the author.