Impact
The Windows installer for the Rakuten Kobo Desktop Application loads Dynamic Link Libraries from the current directory without validating the path. When a malicious DLL with the same name as a legitimate dependency is placed in the installer’s directory, the loader resolves the DLL, allowing the attacker to execute arbitrary code. Since the installer operates with the privileges of the user performing the installation, any code executed can run with that user’s rights, potentially including administrative privileges if the installer is executed under an admin account.
Affected Systems
Rakuten Kobo Inc’s Rakuten Kobo Desktop Application for Windows is affected. The vulnerability applies to the installer component, but specific product versions and build numbers are not listed in the advisory.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability, and with an EPSS score of 0.00181, indicating a low probability of exploitation, the lack of listing in the CISA KEV catalog suggests it is not currently known to be actively exploited in the wild. However, an attacker can exploit this weakness during the installation process by simply dropping a crafted DLL into the installer’s directory. Successful exploitation requires local access to the machine where the installer is launched, but can be triggered remotely if an attacker can persuade a user to run the installer.
OpenCVE Enrichment