CVE-2024-38177HighCVSS 7.8

Windows App Installer Spoofing Vulnerability

Published
August 13, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The attacker must convince a user to call Windows App Installer with a specially crafted malicious winget file.

How can I find more information regarding Windows App Installer and Winget? Please read this page to understand more about App Installer: Installing the App Installer.

🎯 Affected products1

  • App Installer

✅ Remediation

KBRelease Notes (Security Update) — fixed build 1.22.11261.0

🔗 References (3)