cvedb.io
CVE-2021-43890
HIGH · CVSS 7.1 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 95%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2021-12-15 · Last modified 2026-08-04T05:16:27.360

Summary

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the

Affected products

Microsoft — Windows

Does this affect you?

Add your gear to cvedb and we'll alert you only when Microsoft ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.