A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ly Corporation
Ly Corporation line For Windows
Vendors & Products Ly Corporation
Ly Corporation line For Windows

Tue, 11 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title DLL Hijacking via Unsecure Msftedit.dll Loading in LINE for Windows

Mon, 10 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title DLL Hijacking via Unsecured DLL Loading in LINE for Windows
Weaknesses CWE-114

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-427
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title DLL Hijacking via Unsecured DLL Loading in LINE for Windows
Weaknesses CWE-114

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: LY-Corporation

Published:

Updated: 2026-08-10T18:02:03.340Z

Reserved: 2026-06-24T06:46:44.264Z

Link: CVE-2026-13133

cve-icon Vulnrichment

Updated: 2026-08-10T18:01:58.664Z

cve-icon NVD

Status : Received

Published: 2026-08-10T07:16:46.173

Modified: 2026-08-10T18:17:39.497

Link: CVE-2026-13133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:26:11Z

Weaknesses