CVE-2026-28704

HIGH

Emocheck - Uncontrolled Search Path Element via DLL Loading

Title source: llm
STIX 2.1

Description

Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with the privilege of the user invoking EmoCheck.

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
Japan Computer Emergency Response Team Coordination Center (JPCERT/CC)/Emocheck all versions
jpcert/emocheck
Published Apr 10, 2026
Tracked Since Apr 10, 2026