Junglewise Threat Intelligence

CVE-2026-28704: JPCERT/CC EmoCheck insecure DLL loading

CVE-2026-28704 · Severity: high · CVSS 7.8 · Published 2026-04-10

Executive brief

EmoCheck, a tool used to detect Emotet malware infections on Windows systems, contains a security flaw in how it loads system files. An attacker could trick a user into downloading a malicious file into the same folder as the tool, allowing the attacker to take control of the computer with the user's permissions. Because the Emotet threat has subsided, the developers have discontinued the tool and recommend all users stop using it immediately.

Technical details

EmoCheck is vulnerable to an uncontrolled search path element (CWE-427), commonly known as DLL hijacking. The application insecurely loads Dynamic Link Libraries (DLLs) from its current working directory rather than using fully qualified paths or secure search order. An attacker can exploit this by placing a malicious DLL in the same directory as the EmoCheck executable and convincing a user to run the application. Successful exploitation results in arbitrary code execution under the security context of the executing user. No patch is available as the product has reached end-of-life; users are advised to discontinue use.

Affected products

  • JPCERT/CC EmoCheck All versions

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: advisory: JPCERT/CC released advisory and announced end-of-life

References