CVE-2024-38177HighCVSS 7.8
Windows App Installer Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The attacker must convince a user to call Windows App Installer with a specially crafted malicious winget file.
How can I find more information regarding Windows App Installer and Winget? Please read this page to understand more about App Installer: Installing the App Installer.
🎯 Affected products1
- App Installer
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.22.11261.0