LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-43890: Microsoft Windows AppX Installer Spoofing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 15, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Dec 29, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-43890 to its Known Exploited Vulnerabilities catalog on Dec 15, 2021, with a federal patch deadline of Dec 29, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

CVE-2021-43890 is a spoofing vulnerability in the Microsoft Windows AppX Installer. An attacker who successfully abuses it can undermine the trust users and systems place in package installation, with high impact on confidentiality, integrity, and availability. CISA has noted known ransomware use associated with this issue, so organizations running Windows should treat it as a priority for inventory and remediation. Confirm all version, configuration, and fix details against the vendor advisory.

How it works

This is a spoofing flaw in the AppX Installer component of Microsoft Windows. Spoofing weaknesses of this class allow an attacker to present malicious or altered content in a way that appears legitimate to the installer or to the user, so that untrusted packages or installation flows may be accepted when they should not be. Public detail on exact exploit mechanics is limited; defenders should assume that a successful attack could lead to unauthorized code or package installation with serious consequences for system integrity and subsequent confidentiality and availability impacts. Do not rely on unconfirmed technical write-ups—validate behavior and attack surface against Microsoft’s advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that use the AppX Installer. AppX-related installation paths are common on modern Windows clients and on servers or workstations where Microsoft Store apps, sideloaded packages, or enterprise app deployment are in use.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory and per CISA’s required action to apply updates per vendor instructions. Use your standard patch deployment ring (test, then pilot, then broad) but accelerate for internet-facing or high-privilege Windows hosts.

If you can't patch immediately

If you cannot deploy the vendor update at once, reduce exposure with compensating controls until you can.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to broader compromise and data exposure. If you have evidence of exploitation or suspicious AppX-related activity, follow your incident response process: isolate affected hosts, preserve logs and disk evidence, reset credentials that may have been at risk, and assess whether ransomware or data theft occurred. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches and to prioritize password and MFA hygiene.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVDec 15, 2021
Federal patch deadlineDec 29, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities