CVE-2021-43890
Microsoft App Installer, app installer, windows 10 1809
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrati...
- CVSS
- 7.1
- EPSS
- 10.3% 95.2% percentile
- CISA KEV
- Listed
- Published
- 2021.12.16