PT-2026-69336 · Line · Line For Windows
CVE-2026-13133
·
Published
2026-08-10
·
Updated
2026-08-10
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
LINE for Windows versions prior to 26.4.0
Description
LineInst.exe loads the
Msftedit.dll library using a relative path without implementing a secure DLL search path. This allows a malicious DLL placed in the installer's directory to be loaded instead of the legitimate copy located in the System32 folder. DLL search order refers to the sequence of directories the operating system searches to find a required library file.Recommendations
Update LINE for Windows to version 26.4.0 or later.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Line For Windows