PT-2026-69336 · Line · Line For Windows

CVE-2026-13133

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions LINE for Windows versions prior to 26.4.0
Description LineInst.exe loads the Msftedit.dll library using a relative path without implementing a secure DLL search path. This allows a malicious DLL placed in the installer's directory to be loaded instead of the legitimate copy located in the System32 folder. DLL search order refers to the sequence of directories the operating system searches to find a required library file.
Recommendations Update LINE for Windows to version 26.4.0 or later.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13133

Affected Products

Line For Windows