CVE-2021-43890 is a spoofing vulnerability in the AppX installer affecting Microsoft Windows, allowing attackers to deliver malware like Emotet/Trickbot/Bazaloader via specially crafted packages. With a CVSS score of 7.1 (High), exploitation requires user interaction (e.g., opening a malicious attachment) but can lead to high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and numerous media reports, and has garnered significant community discussion. Microsoft has since disabled the ms-appinstaller protocol by default to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16CPE matchmatch criteria | cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:* | ||
< 1.11CPE matchmatch criteria | cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.