CVE-2021-43890 Details
Description
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.
A spoofing vulnerability has been identified in the AppX installer for Microsoft Windows. This vulnerability allows attackers to craft malicious packages that can bypass standard security measures and deliver malware, including families like Emotet, TrickBot, and BazarLoader. The vulnerability is particularly concerning because it can be exploited through social engineering tactics, convincing users to open harmful attachments. While users with lower privileges may face reduced risk, those with administrative rights are more vulnerable.
Users can update to the latest version of the App Installer, version 1.21.3421.0 or greater, which disables the ms-appinstaller protocol by default. For enterprise environments, the Group Policy 'EnableMSAppInstallerProtocol' can be set to 'Disabled' to prevent the protocol from being used. Customers who cannot immediately update the App Installer can apply workarounds, such as blocking non-admin users from installing Windows App packages or using Windows Defender Application Control or AppLocker to block the Desktop App Installer.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 14, 2021References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Windows AppX Installer Spoofing Vulnerability | Dec 15, 2021 | Dec 29, 2021 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft app installer | < 1.16 < 1.11 |
CPE
Remediation
| |
| microsoft windows 10 1809 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1903 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1909 | All versions |
CPE
Remediation
| |
| microsoft windows 10 2004 | All versions |
CPE
Remediation
| |
| microsoft windows 10 20h2 | All versions |
CPE
Remediation
| |
| microsoft windows 10 21h1 | All versions |
CPE
Remediation
| |
| microsoft windows 10 21h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 21h2 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1507 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1709 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1803 | All versions |
CPE
Remediation
| |
Change History
22 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 25, 2026 | Modified Analysis | [email protected] |
| Feb 24, 2026 | CVE Modified | [email protected] |
| Oct 30, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 7, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 24, 2024 | Modified Analysis | [email protected] |
| May 29, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 30, 2023 | CVE Modified | [email protected] |
| Dec 28, 2023 | CVE Modified | [email protected] |
| Jul 12, 2022 | CWE Remap | [email protected] |
| Jan 1, 2022 | Modified Analysis | [email protected] |
| Dec 29, 2021 | CVE Modified | [email protected] |
| Dec 23, 2021 | Initial Analysis | [email protected] |