CVE-2026-28704 Details
Description
Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with the privilege of the user invoking EmoCheck.
A vulnerability exists in EmoCheck, a tool for detecting Emotet malware infections, due to insecure loading of Dynamic Link Libraries (DLLs). This flaw allows arbitrary code to be executed with the privileges of the user running EmoCheck. The vulnerability arises from an uncontrolled search path element, enabling the execution of crafted DLL files placed in the same directory as the application.
Users are advised to stop using EmoCheck, as the tool is no longer available. For those who have been using it, immediate cessation of use is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/JPCERTCC/EmoCheck/ | [email protected] | Product |
| https://jvn.jp/en/jp/JVN00263243/ | [email protected] | Third Party Advisory |
| https://www.jpcert.or.jp/press/2026/PR20260410.html | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jpcert emocheck | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | New CVE Received | [email protected] |