U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-43890

Change History

Modified Analysis by NIST 7/24/2024 12:52:54 PM

Action Type Old Value New Value
Changed CPE Configuration
AND
     OR
          cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*
          cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:*
     OR
          *cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:* versions up to (excluding) 1.16
     OR
          cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_1909:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_2004:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_20h2:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_21h1:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_11_21h2:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:* versions up to (excluding) 1.11
     OR
          cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:*
Changed Reference Type
https://github.com/ChrisTitusTech/winutil/pull/26 No Types Assigned
https://github.com/ChrisTitusTech/winutil/pull/26 Issue Tracking
Changed Reference Type
https://thehackernews.com/2023/12/microsoft-disables-msix-app-installer.html No Types Assigned
https://thehackernews.com/2023/12/microsoft-disables-msix-app-installer.html Press/Media Coverage, Third Party Advisory
Changed Reference Type
https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-msix-protocol-handler-abused-in-malware-attacks/ No Types Assigned
https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-msix-protocol-handler-abused-in-malware-attacks/ Press/Media Coverage, Third Party Advisory
Changed Reference Type
https://www.microsoft.com/en-us/security/blog/2023/12/28/financially-motivated-threat-actors-misusing-app-installer/ No Types Assigned
https://www.microsoft.com/en-us/security/blog/2023/12/28/financially-motivated-threat-actors-misusing-app-installer/ Exploit, Vendor Advisory