Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-43890— Windows AppX Installer Spoofing Vulnerability

Quick assessment

Affected
Microsoft App Installer
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Windows AppX Installer是美国微软(Microsoft)公司的一款免费的 Microsoft 安装应用。用于在 Windows 10 上安装 Appx 应用。 Microsoft Windows AppX Installer 存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。

CVSS 7.1 · High KEV · Ransomware EPSS 10.29% · P95

Affected Version Matrix 1

VendorProduct Version RangeStatus
Microsoft App Installer 1.0.0.0< publication affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-43890

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Windows AppX Installer Spoofing Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows AppX Installer 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows AppX Installer是美国微软(Microsoft)公司的一款免费的 Microsoft 安装应用。用于在 Windows 10 上安装 Appx 应用。 Microsoft Windows AppX Installer 存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Microsoft App Installer 1.0.0.0 ~ publication cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2021-43890

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-43890

登录查看更多情报信息。

Patches & Fixes for CVE-2021-43890 (1)

Vendor Advisories for CVE-2021-43890 (1)

Security Blog Posts for CVE-2021-43890 (1)

News Coverage for CVE-2021-43890 (2)

Same Patch Batch · Microsoft · 2021-12-15 · 67 CVEs total

CVE-2021-42313 10.0 CRITICAL Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42311 10.0 CRITICAL Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-43215 9.8 CRITICAL iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
CVE-2021-43907 9.8 CRITICAL Visual Studio Code WSL Extension Remote Code Execution Vulnerability
CVE-2021-43899 9.8 CRITICAL Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability
CVE-2021-43905 9.6 CRITICAL Microsoft Office app Remote Code Execution Vulnerability
CVE-2021-43882 9.0 CRITICAL Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42315 8.8 HIGH Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42314 8.8 HIGH Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-41365 8.8 HIGH Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42309 8.8 HIGH Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-43877 8.8 HIGH ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-43217 8.1 HIGH Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
CVE-2021-42310 8.1 HIGH Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2021-42320 8.0 HIGH Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-43232 7.8 HIGH Windows Event Tracing Remote Code Execution Vulnerability
CVE-2021-43226 7.8 HIGH Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-43231 7.8 HIGH Windows NTFS Elevation of Privilege Vulnerability
CVE-2021-43223 7.8 HIGH Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-43230 7.8 HIGH Windows NTFS Elevation of Privilege Vulnerability

Showing top 20 of 67 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-43890

No comments yet


Leave a comment