Junglewise Threat Intelligence

CVE-2021-43890: Microsoft Windows AppX Installer Spoofing Vulnerability

CVE-2021-43890 · Severity: critical · CVSS 7.1 · Exploited in the wild · Published 2021-12-15

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft Windows AppX Installer contains a spoofing vulnerability that allows attackers to craft malicious attachments for phishing campaigns. Exploitation involves convincing a user to open a specially crafted package, which has been observed in the wild delivering malware families such as Emotet, Trickbot, and Bazaloader.

Affected products

  • Microsoft Windows AppX Installer

Timeline

  • 2021-12-15: disclosed
  • 2021-12-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-12-15: advisory
  • 2023-12-27: other: Microsoft updated App Installer to disable the ms-appinstaller protocol by default due to increased abuse.

Related threats