CVE-2026-68955: High severity Rakuten Kobo Desktop Application (Windows) vulnerability
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
A crafted DLL must be present in the same directory as the affected installer, and a user must invoke that installer. The attack requires user interaction.
Does exploitation require prior privileges or network access?
The CVSS vector indicates local attack access and no privileges required. The issue is not described as remotely exploitable over the network.
What level of access could successful exploitation provide?
Arbitrary code may execute with the privileges of the user performing the installation. The stated impact includes high confidentiality, integrity, and availability effects.