ADVERTISEMENT. Windows administrators may have similar feelings to Murray's in regards to vulnerability CVE-2021-43890.
First patched in December 2021, Microsoft announced in December 2023 that it has detected attacks in the wild and patched the issue again.
What Microsoft failed to mention is that the first patch has somehow been undone since April 2023.
The vulnerability report refers to the issue as a spoofing vulnerability in Appx installer in Microsoft Windows.
Microsoft developed the ms-appinstaller Uniform Resource Identifier to support the downloading and installation of apps directly from Internet servers.
A click on the x-icon at the top of the window cancelled the process.
Activation of install would download and install the malware on the device.
Microsoft's blog post on its Security blog reveals that it observed several attacks that make use of App Installer to infect Windows devices.
The functionality is disabled by default according to this Microsoft support page.
What Microsoft fails to mention in the post is that it disabled the functionality in December 2021 already as a reaction to abuse of the functionality.
Will Dormann was among the first to spot this missing piece of information in Microsoft's announcement.
What Microsoft also does not reveal in its announcement is when it disabled the functionality by default.
Günter Born thinks that the December 2023 security updates are the most likely option, but Microsoft never revealed this.
The description informs the user that the protocol has been disabled.
System administrators may want to read through Microsoft's entire post on the Security blog.
It includes information about three malwares that used the vulnerability as well as a long list of recommendations.
More than half of Microsoft's suggestions are about educating users.
Open a command prompt window, e.g., by opening Start, typing cmd and selecting Command Prompt from the options.
You can upgrade the application using the command winget upgrade Microsoft.
Microsoft has posted a warning about attacks that target the Windows feature App Installer, but failed to mention that it addressed it previously already.
This Cyber News was published on www.ghacks.net. Publication date: Fri, 29 Dec 2023 12:13:04 +0000