CVE-2026-13133

8.4

LY Corporation · LINE for Windows

A vulnerability in LINE for Windows allows for local privilege escalation or arbitrary code execution by leveraging improper file path handling during the installation process.

Executive summary

A high-severity vulnerability in LINE for Windows could allow a local attacker to execute arbitrary code or gain elevated privileges due to insecure library loading.

Vulnerability

This issue involves an insecure search path (CWE-427) within the installation utility, LineInst. The vulnerability requires user interaction and can be exploited by an attacker with local access to the system.

Business impact

An attacker who successfully exploits this vulnerability could execute code with the privileges of the victim, potentially leading to unauthorized access to sensitive communications or system compromise. With a CVSS score of 8.4, this vulnerability is significant, particularly in environments where multiple users share workstations or where endpoint security is limited.

Remediation

Immediate Action: Update the LINE for Windows application to version 26.4.0 or later to ensure the vulnerability is patched.

Proactive Monitoring: Review endpoint security logs for unexpected process execution or file modification events originating from the LINE installation directory.

Compensating Controls: Enforce strict file system permissions on installation directories and utilize application whitelisting to prevent the execution of unauthorized binaries.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

While this vulnerability requires local access, the potential for privilege escalation makes it a priority for workstation security. Organizations should ensure that users are updated to the latest version of LINE to eliminate this vector of attack.

More LY Corporation CVEs