Microsoft disables the ms-appinstaller protocol because it was abused to spread malware
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-43890 | Spoofing Vulnerability in Microsoft Windows AppX Installer Actively Exploited CVE-2021-43890 is a spoofing vulnerability in the AppX Installer (App Installer) component of Microsoft Windows that allows a specially crafted package to masquerade as a trusted application. Triggering it requires user interaction: an attacker distributes a malicious installer package or ms-appinstaller link, typically via phishing, and must convince the user to open it, with impact limited to the privileges of the affected account. Successful exploitation delivers malware — Microsoft observed the Emotet, Trickbot and BazaLoader families in these attacks — and the flaw has also been used in ransomware campaigns, with users operating with administrative rights facing greater impact than low-privileged users. Essentially any Windows system relying on App Installer is affected; the exact affected build ranges are not enumerated in the advisory data, though contemporaneous headlines characterized it as an actively exploited Windows 10 zero-day addressed in the December 2021 Patch Tuesday. Exploitation is confirmed in the wild: CISA added it to KEV on 2021-12-15 with known ransomware use (EPSS 10.3% / 95th percentile), and in late 2023 Microsoft Threat Intelligence reported renewed abuse of the ms-appinstaller URI scheme and disabled that protocol by default in the updated App Installer. Do: Apply Microsoft's security updates per the vendor advisory (December 2021 Windows updates) and install the updated App Installer using the Microsoft Store links in the advisory. Verify the updated App Installer is in place and that the ms-appinstaller protocol handler is disabled — it is disabled by default in the December 27, 2023 App Installer update. Because exploitation depends on users opening crafted packages, prioritize patching systems where users run with administrative rights and remind users to treat app-installer links and attachments arriving via email or chat with caution. | 7.1 | 10% | KEV ransomware PoC |
| mass~1 billion+ Windows devices (App Installer ships as a built-in Windows component) |
Full article437 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
February 07, 2022

Microsoft temporarily disabled the ms-appinstaller protocol for MSIX because it was abused by malware, such as Emotet.
Microsoft announced to have temporarily disabled the ms-appinstaller protocol for MSIX because it was abused by malware, such as Emotet.
In December, Microsoft addressed a vulnerability, tracked as CVE-2021-43890, in AppX installer that affects Microsoft Windows which is under active exploitation.
“We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader.” reads the advisory published by Microsoft.
An attacker could exploit the vulnerability by tricking the victims into opening a specially crafted attachment sent via phishing messages.
Microsoft reported that the issue was exploited by threat actors to deliver Emotet, TrickBot, and BazarLoader malware.
MSIX is a new packaging format based on the .msi installer, .appx, installer, App-V, and ClickOnce installers. MSIX keeps the functionality of the existing app installer packages and installation files while enabling new and modern packaging and deployment features to Win32, WPF, and WinForm apps.
The ms-appinstaller protocol handler allows users to simply install an application by clicking a link on a website, it doesn’t require downloading the full MSIX package.
Due to this capability, threat actors started abusing the protocol in malspam campaigns.
The IT giant opted out to temporarily disable the protocol to prevent these malware campaigns.
“We were recently notified that the ms-appinstaller protocol for MSIX can be used in a malicious way. Specifically, an attacker could spoof App Installer to install a package that the user did not intend to install.” reads the advisory published by Microsoft. “For now, we have disabled the ms-appinstaller scheme (protocol). This means that App Installer will not be able to install an app directly from a web server. Instead, users will need to first download the app to their device, and then install the package with App Installer. This may increase the download size for some packages.”
Microsoft is conducting testing to securely re-enable the protocol, the company planning to introduce a Group Policy that would allow IT administrators to re-enable the protocol and control usage of it within their organizations.
Users that utilize the ms-appinstaller protocol on their website are recommended to update the link to their application, removing ‘ms-appinstaller:?source=’ so that the MSIX package or App Installer file will be downloaded to user’s machine.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Microsoft)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/127755/malware/microsoft-disables-ms-appinstaller.html