« Volver al listado

Microsoft

Microsoft APP Installer: vulnerabilidades y CVE

Microsoft APP Installer tiene 3 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE3
Últimos 12 meses1
Críticas0
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-43890Alta (7.1)10%⚠ Explotación activa15 dic 2021
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-68821Alta (7.8)0.32%—11 ago 2026
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
CVE-2024-38177Alta (7.8)0.86%—13 ago 2024
Windows App Installer Spoofing Vulnerability
CVE-2021-43890Alta (7.1)10%⚠ Explotación activa15 dic 2021
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution1
  2. T1204.002 Malicious File1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft