ZeroHour

CVE-2021-43890

KEV ransomware PoC mass1

Spoofing Vulnerability in Microsoft Windows AppX Installer Actively Exploited

CISA: Microsoft Windows AppX Installer Spoofing Vulnerability

CVSS 3.1
7.1 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2021-43890 is a spoofing vulnerability in the AppX Installer (App Installer) component of Microsoft Windows that allows a specially crafted package to masquerade as a trusted application. Triggering it requires user interaction: an attacker distributes a malicious installer package or ms-appinstaller link, typically via phishing, and must convince the user to open it, with impact limited to the privileges of the affected account. Successful exploitation delivers malware — Microsoft observed the Emotet, Trickbot and BazaLoader families in these attacks — and the flaw has also been used in ransomware campaigns, with users operating with administrative rights facing greater impact than low-privileged users. Essentially any Windows system relying on App Installer is affected; the exact affected build ranges are not enumerated in the advisory data, though contemporaneous headlines characterized it as an actively exploited Windows 10 zero-day addressed in the December 2021 Patch Tuesday. Exploitation is confirmed in the wild: CISA added it to KEV on 2021-12-15 with known ransomware use (EPSS 10.3% / 95th percentile), and in late 2023 Microsoft Threat Intelligence reported renewed abuse of the ms-appinstaller URI scheme and disabled that protocol by default in the updated App Installer.

What to do: Apply Microsoft's security updates per the vendor advisory (December 2021 Windows updates) and install the updated App Installer using the Microsoft Store links in the advisory. Verify the updated App Installer is in place and that the ms-appinstaller protocol handler is disabled — it is disabled by default in the December 27, 2023 App Installer update. Because exploitation depends on users opening crafted packages, prioritize patching systems where users run with administrative rights and remind users to treat app-installer links and attachments arriving via email or chat with caution.

Affected
microsoft App Installer (AppX Installer)
microsoft Windows
Estimated exposure
mass~1 billion+ Windows devices (App Installer ships as a built-in Windows component) — App Installer is bundled with Windows 10/11, which run on an estimated ~1.4 billion active Windows devices, and CISA's KEV listing reflects a ubiquitous, actively exploited component rather than a niche deployment.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
app installer
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news