Newly Patched Windows Vulnerability (CVE-2021-43890) Being Exploited to Deliver Malware

Description

FortiGuard Labs is aware of a report that a newly patched Windows vulnerability (CVE-2021-43890) is being exploited in the wild to deliver malware such as Emotet, Trickybot and Bazaloader. Exploiting CVE-2021-43890 allows an attacker to create a malicious package file that looks like a legitimate application. The vulnerability is patched as part of MS Tuesday in December 2021.


Why is this Significant?

This is significant because CVE-2021-43890 was abused as a zero-day to deliver Emotet, Trickybot and Bazaloader. Those malware typically deploy additional malware including ransomware to a compromised machine.


What is CVE-2021-43890?

CVE-2021-43890 is Windows AppX Installer Spoofing Vulnerability that allows an attack to spoof a malicious package as legitimate software. For example, an attacker can abuse CVE-2021-43890 to create a fake malicious package that has an icon of legitimate software, a valid certificate that marks the package as a Trusted App along with fraudulent publisher information. These pieces increase the chance of convincing the victim to run the file.



Image of "Windows AppX Installer abuse to install Emotet" courtesy of BleepingComputer


Microsoft rates this vulnerability as important.


Has the Vendor Released a Fix for the Vulnerability?

Yes, Microsoft released a fix on December 14th, 2021, as part of December Patch Tuesday.


What is the Status of Coverage?

There is not sufficient information available yet that enables FortiGuard Labs to develop IPS protection for CVE-2021-43890.


FortiGuard Labs provides the following AV coverage against malware that abuses CVE-2021-43890:

W32/GenCBL.BHP!tr

W32/Kryptik.HNMX!tr