Microsoft
Microsoft APP Installer: vulnerabilities and CVEs
Microsoft APP Installer has 3 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.
CVEs3
Last 12 months1
Critical0
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43890 | High (7.1) | 10% | ⚠ Active exploitation | Dec 15, 2021 | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-68821 | High (7.8) | 0.32% | — | Aug 11, 2026 | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. |
| CVE-2024-38177 | High (7.8) | 0.86% | — | Aug 13, 2024 | Windows App Installer Spoofing Vulnerability |
| CVE-2021-43890 | High (7.1) | 10% | ⚠ Active exploitation | Dec 15, 2021 | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.