BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2021
CVE-2021-43890High confidence

Microsoft Windows AppX Installer Spoofing Vulnerability

Microsoft · Windows

7.1HighCVSS 3.1
Recommended action
Patch now

CISA confirms exploitation in the wild and lists 2021-12-29 as the remediation due date.

Patch available
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2021-30752

CISA KEV mirrored by ENISA

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 15 Dec 2021. Evidence sources: cisa_kev.
ENISA score
7.1 · CVSS 3.1
Advisory evidence
No linked advisory details stored yet
Recommended actionPatch now

CISA confirms exploitation in the wild and lists 2021-12-29 as the remediation due date.

Patch available
01

What, why and how

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

What

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

Why

The current structured CVE record identifies a security weakness, but the root cause requires confirmation in the linked vendor material.

How

An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

Why

The current structured CVE record identifies a security weakness, but the root cause requires confirmation in the linked vendor material.

How

An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2021-12-15. Known ransomware campaign use is recorded.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → vulnerable operation → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
Low: a basic authenticated account is required
User interaction
Required interaction required
Attack complexity
High: exploitation depends on specific conditions
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration.
CWE not yet assigned
CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACHighAttack complexity: Successful exploitation depends on specific conditions outside the attacker's direct control.PRLowPrivileges required: The attacker needs basic user-level privileges.UIRequiredUser interaction: Another user must perform an action for exploitation to succeed.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkCISA KEVPublic exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2021-30752Known-exploited evidence recorded

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations.

Official EUVD record ↗
Canadian Centre for Cyber Security · English · AV21-631Microsoft security advisory – December 2021 monthly rollup

On 14 December 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following: Exploitation of some of these vulnerabilities could allow an actor to execute code remotely.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-961Multiples vulnérabilités dans les produits Microsoft

d?id=CVE-2021-43214 Référence CVE CVE-2021-43243 https://www.cve.org/CVERecord?id=CVE-2021-43243 Référence CVE CVE-2021-43255 https://www.cve.org/CVERecord?id=CVE-2021-43255 Référence CVE CVE-2021-43256 https://www.cve.org/CVERecord?id=CVE-2021-43256 Référence CVE CVE-2021-43875 https://www.cve.org/CVERecord?id=CVE-2021-43875 Référence CVE CVE-2021-43877 https://www.cve.org/CVERecord?id=CVE-2021-43877 Référence CVE CVE-2021-43882 https://www.cve.org/CVERecord?id=CVE-2021-43882 Référence CVE CVE-2021-43888 https://www.cve.org/CVERecord?id=CVE-2021-43888 Référence CVE CVE-2021-43889 https://www.cve.org/CVERecord?id=CVE-2021-43889 Référence CVE CVE-2021-43890 https://www.cve.org/CVERecord?id=CVE-2021-43890 Référence CVE CVE-2021-43891 https://www.cve.org/CVERecord?id=CVE-2021-43891 Référence CVE CVE-2021-43892 https://www.cve.org/CVERecord?id=CVE-2021-43892 Référence CVE CVE-2021-43896 https://www.cve.org/CVERecord?id=CVE-2021-43896 Référence CVE CVE-2021-43899 https://www.cve.org/CVERecord?id=CVE-2021-43899 Référence CVE CVE-2021-43907 https://www.cve.org/CVERecord?id=CVE-2021-43907 Référence CVE CVE-2021-43908 https://www.cve.org/CVERecord?id=CVE-2021-43908 Gestion détaillée du document le 15 décembre 2021 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générale

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2021-006059App Installer におけるなりすまされる脆弱性

App Installer には、なりすまされる脆弱性が存在します。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6102MS 2월 보안 위협에 따른 정기 보안 업데이트 권고

Data.SqlClient SQL 데이터 공급자 보안 기능 바이패스 취약성 | | Role: DNS Server | CVE-2023-50387 | MITRE: CVE-2023-50387 DNS RRSIG 및 DNSKEY 유효성 검사를 악용하여 DNS 서버 리소스를 원격으로 이용할 수 있습니다. | | ASP.NET | CVE-2023-36558 | ASP.NET Core - 보안 기능 바이패스 취약성 | | .NET Framework | CVE-2023-36049 | .NET, .NET Framework, Visual Studio 권한 상승 취약성 | | Microsoft Power Platform Connector | CVE-2023-36019 | Microsoft Power Platform Connector 스푸핑 취약성 | | Visual Studio Code | CVE-2023-36018 | Visual Studio Code Jupyter 확장 스푸핑 취약성 | | Windows Secure Boot | CVE-2023-24932 | 보안 부팅 보안 기능 우회 취약성 | | Microsoft Bluetooth Driver | CVE-2023-24023 | Mitre: CVE-2023-24023 Bluetooth 취약성 | | Apps | CVE-2021-43890 | Windows AppX 설치 관리자 스푸핑 취약성 | ##### □ 작성 : 취약점분석팀

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6055MS 12월 보안 위협에 따른 정기 보안 업데이트 권고

re Connected Machine 에이전트 권한 상승 취약성 | | Microsoft Windows DNS | CVE-2023-35622 | Windows DNS 스푸핑 취약성 | | Microsoft Dynamics | CVE-2023-35621 | Microsoft Dynamics 365 금융 및 운영 서비스 거부 취약성 | | Microsoft Office Outlook | CVE-2023-35619 | Mac용 Microsoft Outlook 스푸핑 취약성 | | Microsoft Edge (Chromium-based) | CVE-2023-35618 | Microsoft Edge(Chromium 기반) 권한 상승 취약성 | | Azure DevOps | CVE-2023-21751 | Azure DevOps Server 스푸핑 취약성 | | Windows Media | CVE-2023-21740 | Windows Media 원격 코드 실행 취약성 | | Chipsets | CVE-2023-20588 | AMD: CVE-2023-20588 AMD 추측성 유출 보안 알림 | | Microsoft Exchange Server | CVE-2022-24477 | Microsoft Exchange Server 권한 상승 취약성 | | Apps | CVE-2021-43890 | Windows AppX 설치 관리자 스푸핑 취약성 | ##### □ 작성 : 취약점분석팀

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5468MS 12월 보안 위협에 따른 정기 보안 업데이트 권고

Windows Server 2019, Windows Server 2016 및 Server Core 설치(2019, 2016, v20H2, v2004) 긴급 원격 코드 실행 Windows 8.1, Windows Server 2012 R2, Windows Server 2012 긴급 원격 코드 실행 Microsoft Office 긴급 원격 코드 실행 Microsoft SharePoint 중요 원격 코드 실행 Microsoft ASP.NET Core 중요 권한 상승 Microsoft Visual Studio 긴급 원격 코드 실행 IoT용 Microsoft Defender 긴급 원격 코드 실행 Microsoft PowerShell 중요 스푸핑 [참고 사이트] [1] (한글) https://portal.msrc.microsoft.com/ko-kr/security-guidance [2] (영문) https://portal.msrc.microsoft.com/en-us/security-guidance [3] https://msrc.microsoft.com/update-guide/releaseNote/2021-Dec [4] https://msrc.microsoft.com/update-guide o 취약점 요약 정보 제품 카테고리 CVE 번호 CVE 제목 Apps CVE-2021-43890 Windows AppX Installer Spoofing Vulnerability ASP.NET Core & Visual Studio CVE-2021-43877 ASP.NET Core 및 Visual Studio 권한 상승 취약성 Azure Bot Framework SDK CVE-2021-43225 봇 프레임워크 SDK 원격 코드 실행 취약성 BizTalk ESB Toolkit CVE-2021-43892 Microsoft BizTalk ESB Toolkit Spoofing Vulnerability Internet Storage Name Service CVE-2021-43215 iSNS 서버 메모리 손상 취약성으로 인한 원격 코드 실행 가능 Microsoft Defender for IoT CVE-2021-43889 IoT용 Microsoft Defender 원격 코드 실행 취약성 Microsoft Defender for IoT CVE-2021-43888 IoT용 Microsoft Defender 정보 유출 취약성 Microsoft Defender for IoT CVE-2021-43882 IoT용 Microsoft Defender 원격 코드 실행 취약성 Microsoft Defender for IoT CVE-2021-42315 IoT용 Micros

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
App Installer: 1.0.0.0 < publication
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 15 Dec 2021 · Last source change 6 Aug 2026, 03:55 UTC · CWE not yet assigned

CVE recordCVE.org · 5.2
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2021-30752
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceUnavailable
NVD statusNVD enriched

Missing structured fields: CWE classification. Missing data is not evidence of low risk; review the primary advisory.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    1.0.0.0 < publication · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    App Installer: 1.0.0.0 < publication · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2021-43890 · cve.blacktree.nl