CVE-2021-43890

HIGH(7.1)KEVRansomwareElevated Risk

Microsoft Windows AppX Installer Spoofing Vulnerability

Description

CVE-2021-43890 is a high-severity spoofing vulnerability in the Microsoft Windows AppX Installer that has been actively exploited in phishing campaigns distributing the Emotet, Trickbot, and Bazaloader malware families. The vulnerability allows an attacker to craft malicious MSIX/AppX packages that appear legitimate, tricking users into installing malware through specially crafted attachments. With a CVSS 3.1 score of 7.1 (HIGH) and an EPSS score of 19.83% (95.4th percentile), this Windows AppX Installer vulnerability represents a significant threat. CISA has added CVE-2021-43890 to its Known Exploited Vulnerabilities catalog, and the vulnerability is associated with known ransomware campaigns.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
December 15, 2021
Due Date
December 29, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftapp installer< 1.16; < 1.11

Multiple CVSS Assessments

Source: [email protected](Secondary)
7.1
HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Source: [email protected](Primary)
7.1
HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

Spoofing Vulnerability

The Microsoft Windows AppX Installer spoofing vulnerability allows attackers to craft malicious application packages that bypass visual trust indicators, making them appear as legitimate software installations. The ms-appinstaller URI scheme handler processes these crafted packages without adequate verification of the package source and authenticity, enabling attackers to deliver malware through what appears to be a standard Windows application installation flow.

Learn more: CVE-2021-43890 — Microsoft Security Advisory

Impact Analysis

CVE-2021-43890 has a CVSS 3.1 score of 7.1 (HIGH), reflecting a serious but exploitation-dependent threat. The attack requires network access with high complexity and some level of authentication, and user interaction is required since victims must open a specially crafted attachment. Confidentiality (High): successful exploitation delivers malware capable of stealing credentials, browser data, and sensitive files from the compromised system. Integrity (High): the Emotet, Trickbot, and Bazaloader families installed through this vulnerability can modify system files, install additional malware, and establish persistent backdoors. Availability (High): ransomware payloads delivered through this attack chain can encrypt user data and render systems inoperable. The ransomware association is confirmed as "Known" in the KEV catalog, and Microsoft reported an increase in threat actor activity abusing the ms-appinstaller protocol through late 2023, leading to the protocol being disabled by default.

Exploit Maturity

CVE-2021-43890 has been actively exploited in widespread phishing campaigns since its disclosure. CISA confirmed active exploitation by listing it in the Known Exploited Vulnerabilities catalog with an accelerated remediation deadline of 2021-12-29, and the vulnerability is flagged as associated with known ransomware campaigns. Public exploitation details are available via Microsoft's threat intelligence blog documenting financially motivated threat actors abusing the ms-appinstaller URI scheme. The EPSS score of 19.83% (95.4th percentile) indicates a high probability of exploitation. Microsoft noted a significant increase in exploitation activity through late 2023, ultimately leading to the decision to disable the ms-appinstaller protocol by default in the December 2023 update.

Remediation

  1. Apply updates per vendor instructions as mandated by CISA KEV. Install the latest Microsoft App Installer update from the Microsoft Store (version 1.16 or later for Windows 10, version 1.11 or later for earlier builds), as detailed in the Microsoft security advisory.
  2. Verify that the ms-appinstaller protocol handler is disabled, which Microsoft set as the default in the December 2023 update. This can be enforced via Group Policy to prevent re-enablement.
  3. Implement email security controls to block or quarantine messages containing MSIX, AppX, and AppBundle attachments, and configure web filters to block downloads of these file types from untrusted sources.
  4. Educate users about the phishing campaigns leveraging this vulnerability, particularly regarding unsolicited application installation prompts and suspicious email attachments.
  5. Monitor endpoints for indicators of compromise associated with Emotet, Trickbot, and Bazaloader, including unusual registry modifications, scheduled tasks, and outbound connections to known command-and-control infrastructure.

Technical Details

CVE-2021-43890 exploits a spoofing weakness in the Microsoft Windows AppX Installer component, specifically in how the ms-appinstaller URI scheme processes application packages. Attackers craft malicious MSIX or AppX packages that exploit the installer's insufficient verification of package source and identity, causing the Windows installation UI to display misleading publisher information. The CVSS vector (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H) shows that while network-accessible, the attack has high complexity, requires some authentication, and depends on user interaction to open the malicious package. The vulnerability has been weaponized by multiple financially motivated threat groups distributing Emotet, Trickbot, and Bazaloader through phishing emails containing links or attachments that trigger the ms-appinstaller protocol. Microsoft's December 2023 update disabled the ms-appinstaller protocol by default as a systemic mitigation against ongoing exploitation.

Frequently Asked Questions

Is CVE-2021-43890 being actively exploited?

Yes. CVE-2021-43890 is listed in the CISA Known Exploited Vulnerabilities catalog with confirmed active exploitation. It has been used in phishing campaigns delivering Emotet, Trickbot, and Bazaloader malware, and is associated with known ransomware campaigns. Microsoft reported increasing exploitation activity through late 2023.

What products are affected by CVE-2021-43890?

CVE-2021-43890 affects the Microsoft App Installer component on Windows. Specifically, versions prior to 1.16 and 1.11 are vulnerable. Any Windows system with the ms-appinstaller protocol handler enabled is potentially at risk.

How do I fix CVE-2021-43890?

Update the Microsoft App Installer to the latest version from the Microsoft Store and verify that the ms-appinstaller protocol handler is disabled (the default since December 2023). Additionally, block MSIX and AppX file types at the email gateway and web proxy level.

How severe is CVE-2021-43890?

CVE-2021-43890 has a CVSS 3.1 score of 7.1 (HIGH). While it requires user interaction to exploit, the vulnerability has been widely used in real-world phishing campaigns delivering ransomware and banking trojans. The 19.83% EPSS score places it in the 95.4th percentile of exploitation probability.

CVSS Score

7.1
HIGH(7.1)

EPSS Score

EPSS Score10.29%
EPSS Percentile95.3%

Dates

PublishedDecember 15, 2021
Last ModifiedAugust 6, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.