CVE-2026-13133
Received Received - Intake

DLL Search Order Hijacking in LINE for Windows

Vulnerability report for CVE-2026-13133, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: LINE Corporation

Description

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
linecorp line_for_windows to 26.4.0 (exc)
linecorp line to 26.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in LineInst.exe (LINE for Windows) prior to version 26.4.0. It involves Msftedit.dll being loaded via a relative path without a secure DLL search path. This allows a malicious DLL placed in the installer's directory to be loaded before the legitimate System32 copy, potentially leading to arbitrary code execution.

Detection Guidance

Check the installed version of LINE for Windows. If it is below 26.4.0, the system is vulnerable. Look for suspicious DLL files in the LINE installer directory that may have been placed maliciously.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code on your system if they place a malicious DLL in the installer's directory. This could lead to unauthorized access, data theft, or system compromise. The high CVSS score of 8.4 indicates significant impact on confidentiality, integrity, and availability.

Compliance Impact

This vulnerability could potentially lead to arbitrary code execution, which may result in unauthorized access to sensitive data. This could impact compliance with GDPR (data protection) and HIPAA (health information privacy) by exposing personal or health data to unauthorized parties.

Mitigation Strategies

Update LINE for Windows to version 26.4.0 or later immediately. Remove any untrusted or suspicious DLL files from the LINE installer directory. Ensure no unauthorized executables are present in the installation path.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13133. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart