VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Patches Actively Exploited CVE-2021-43890

high vulnerability

IPA warns that Microsoft's December 2021 patches fix a Windows AppX Installer flaw (CVE-2021-43890) already being exploited in the wild.

On December 15, 2021, Microsoft released its monthly security updates addressing multiple vulnerabilities across its product line. IPA (Japan's Information-technology Promotion Agency) highlighted CVE-2021-43890, a Windows AppX Installer spoofing vulnerability, as confirmed by Microsoft to be under active exploitation in the wild.

Successful exploitation of the flaws in this patch batch could allow attackers to crash applications or gain control over affected systems. Given the active exploitation status of CVE-2021-43890, IPA urged users and administrators to apply Microsoft's patches immediately via Windows Update to prevent further damage.

No specific threat actor, malware family, or targeted sector was identified in this advisory; it serves as a general patch-now notice to the public and enterprise IT administrators.

Mentioned in this report

Vulnerabilities CVE-2021-43890KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211215-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free