Microsoft kills off Windows app installation from the web, again
ID: 81cf54bf-b6b0-58b5-ad8c-ac5a7954bf9f
STIX ID: report--81cf54bf-b6b0-58b5-ad8c-ac5a7954bf9f
Feed Name: The Register (Security)
Threat Score
Microsoft disabled the ms-appinstaller URI scheme after threat actors abused the App Installer web-based install mechanism to distribute malware and bypass SmartScreen and browser warnings. The company plans to revoke abused code-signing certificates, recommends updating vulnerable App Installer versions and applying Group Policy controls, and has re-enabled the protocol for select enterprise customers with explicit policy settings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
