Executive brief
Microsoft Windows AppX Installer contains a spoofing vulnerability that allows attackers to craft malicious attachments for phishing campaigns. Exploitation involves convincing a user to open a specially crafted package, which has been observed in the wild delivering malware families such as Emotet, Trickbot, and Bazaloader.
Affected products
- Microsoft Windows AppX Installer
Timeline
- 2021-12-15: disclosed
- 2021-12-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-15: advisory
- 2023-12-27: other: Microsoft updated App Installer to disable the ms-appinstaller protocol by default due to increased abuse.