Microsoft Windows AppX Installer Spoofing Vulnerability
CVE-2021-43890 is a security vulnerability in Microsoft Windows, added to CISA KEV on December 15, 2021. Patch priority: Patch now. Known ransomware use: yes.
What it is
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
Known to be used in ransomware campaigns. Active threat actors have chained this vulnerability into ransomware operations — treat patching as a same-week priority, not a "next maintenance window" task. The fix is the same one below; the urgency is higher.
VulnCheck tracked exploitation 1 day before CISA's KEV listing. VulnCheck's broader catalog of in-the-wild exploitation evidence picked this up before it landed on CISA's formal list. Per-CVE fact about this entry; not a population claim about lead time in general.
Who's affected
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
What to do
Apply updates per vendor instructions.
If you don't have someone in-house to verify the patch deployed across every endpoint — or you're not sure whether you're affected — that's exactly the kind of triage we do. Book a free 20-minute triage call.
Insurance readiness
Your insurer will ask if this is patched.
Unpatched entries on CISA's Known Exploited Vulnerabilities list are exactly what cyber-insurance carrier questionnaires probe for, and knowing which controls they check is how you keep a renewal from stalling.
Get the free carrier questionnaire →Severity
CVSS base score: 7.1 — HIGH
Microsoft fix
- Release Notes (Security Update)
Microsoft Exploitability Index (assessed at update release): Exploitation Detected
Microsoft has confirmed in-the-wild exploitation in the latest software release. This aligns with CISA's listing of this CVE.
Vendor workaround
Vendor-published workaround
Customers who are unable to install the updates for the Microsoft App Installer can apply the following workarounds to be protected from the vulnerability:
Enable the following GPO to prevent non-admins from installing any Windows App packages
| Policy I Description | |
|---|---|
| BlockNonAdminUserInstall | This policy setting manages the ability of non-administrator users to install (signed) Windows app packages. When enabled (value: 1), non-administrator users will be unable to initiate the installation of (signed) Windows app packages. Administrator users will still be able to initiate the installation of (signed) Windows app packages in Administrator-context. When disabled (value: 0), or not configured, all users will be able to initiate the installation of (signed) Windows app packages. |
Enable this GPO to prevent installing apps from outside the Microsoft Store
| Policy | Description |
|---|---|
| AllowAllTrustedAppToInstall | This policy setting allows you to manage the installation of trusted line-of-business (LOB) or developer-signed Windows Store apps. If you enable this policy setting, you can install any LOB or developer-signed Windows Store app (which must be signed with a certificate chain that can be successfully validated by the local computer). If you disable or do not configure this policy setting, you cannot install LOB or developer-signed Windows Store apps in Administrator-context. When disabled (value: 0), or not configured, all users will be able to initiate the installation of (signed) Windows app packages. |
Use Windows Defender Application Control or AppLocker to block the Desktop App Installer app (Microsoft.DesktopAppInstaller_8wekyb3d8bbwe), or create policies to limit the apps installed in your environment
Disable the ms-appinstaller protocol to install apps directly from a website
Enterprise Administrators can also use Group Policy to prevent users from invoking any protocol handler within the browser.
For Edge browser, add a policy rule for
ms-appinstaller:*
This will block all attempts to invoke the protocol from the browser. Specifically, how that looks to the user will depend on the construction of the page that tries to launch the protocol.
If the page tries to invoke the protocol by navigating a hidden/tiny subframe, the block will appear to be silent.
Vendor-published mitigation
Install the latest App Installer
The best mitigation is to install the latest App Installer build 1.21.3421.0 or greater. The ms-appinstaller URI scheme handler has been disabled by default in the latest build of the App. For more information on how to upgrade the App Installer, please see: Install and update the App Installer.
Disable the protocol
If you have version 1.17.10633.0 or greater of the App Installer, you can disable the protocol immediately in your enterprise environment, by setting the Group Policy EnableMSAppInstallerProtocol to Disabled. See Policy CSP – DesktopAppInstaller for additional information. Customers who require a version of the App Installer prior to 1.17.10633.0 should employ the workarounds described in the Workarounds section of this CVE.
A workaround reduces exposure while you patch — it is not a substitute for the update. Install the fix above as soon as you can.
CISA due date
Federal deadline: December 29, 2021. Federal agencies must complete the required action by this date. For private SMBs the deadline is advisory — but treat it as a strong recommendation, especially if you handle regulated data (HIPAA, GLBA, ABA model rules).
EPSS
EPSS score: 10.3% — higher than 95% of all scored CVEs.
EPSS estimates the probability of exploitation activity in the next 30 days. Every entry on this site is already confirmed exploited, so read it as relative urgency among the things you still have open, not as permission to wait.
Other exploited Microsoft Windows entries
More CISA KEV entries for Microsoft Windows. Same product line, same actively-exploited status.
Source
This entry comes from CISA's Known Exploited Vulnerabilities catalog, public US-Government data we pull daily. The plain-language framing and the what-to-do guidance above are ours. View the original entry on cisa.gov.
