# Microsoft Patches Actively Exploited CVE-2021-43890

Published: 2021-12-14 · Severity: high
Canonical: https://vorant.io/reports/f7a8ab47-4750-5134-a2b9-4a9f57e0813d/microsoft-patches-actively-exploited-cve-2021-43890

> IPA warns that Microsoft's December 2021 patches fix a Windows AppX Installer flaw (CVE-2021-43890) already being exploited in the wild.

On December 15, 2021, Microsoft released its monthly security updates addressing multiple vulnerabilities across its product line. IPA (Japan's Information-technology Promotion Agency) highlighted CVE-2021-43890, a Windows AppX Installer spoofing vulnerability, as confirmed by Microsoft to be under active exploitation in the wild.

Successful exploitation of the flaws in this patch batch could allow attackers to crash applications or gain control over affected systems. Given the active exploitation status of CVE-2021-43890, IPA urged users and administrators to apply Microsoft's patches immediately via Windows Update to prevent further damage.

No specific threat actor, malware family, or targeted sector was identified in this advisory; it serves as a general patch-now notice to the public and enterprise IT administrators.

## Mentioned in this report

- Vulnerabilities: CVE-2021-43890 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20211215-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f7a8ab47-4750-5134-a2b9-4a9f57e0813d/microsoft-patches-actively-exploited-cve-2021-43890.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
