Microsoft disables MSIX protocol handler in Windows to thwart malware attacks
The Windows AppX Installer spoofing vulnerability has been used by malicious actors for quite some time. Microsoft documented it as CVE-2021-43890 a couple of years ago. Back then, attackers were crafting packages containing ransomware that was distributed by exploiting this vulnerability, with Microsoft recommending customers to either install the latest version of the Installer or disable the ms-appinstaller protocol using Group Policy completely. Now, Microsoft has once again issued guidance regarding the vulnerability following a recent resurgence in its exploitation.
The Windows AppX Installer spoofing vulnerability has been used by malicious actors for quite some time. Microsoft documented it as CVE-2021-43890 a couple of years ago. Back then, attackers were crafting packages containing ransomware that was distributed by exploiting this vulnerability, with Microsoft recommending customers to either install the latest version of the Installer or disable the ms-appinstaller protocol using Group Policy completely. Now, Microsoft has once again issued guidance regarding the vulnerability following a recent resurgence in its exploitation.
Sophia Wilson
Atlanta
Atlanta
Published by: aplhsindia.in
