What is CVE-2026-13133?
This vulnerability exists in LineInst.exe (LINE for Windows) versions prior to 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path. This allows a malicious DLL placed in the installer's directory to be loaded instead of the legitimate system copy. Users should immediately update to the latest version.
Azərbaycanca: Bu zəiflik LINE for Windows tətbiqinin 26.4.0 versiyasından əvvəlki LineInst.exe quraşdırıcısında aşkarlanıb. Quraşdırıcı, təhlükəsiz DLL axtarış yolu istifadə etmədən Msftedit.dll faylını nisbi yol ilə yüklədiyi üçün, zərərli DLL quraşdırma qovluğuna yerləşdirilərək icra oluna bilər. İstifadəçilər dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which application's installer was CVE-2026-13133 discovered?
This vulnerability was discovered in the LineInst.exe installer of the LINE for Windows application.
What should users do to protect against CVE-2026-13133?
Users should immediately update to version 26.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.