logo

Microsoft kills off Windows app installation from the web, again

ID: 81cf54bf-b6b0-58b5-ad8c-ac5a7954bf9f

STIX ID: report--81cf54bf-b6b0-58b5-ad8c-ac5a7954bf9f

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-01-04

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Microsoft disabled the ms-appinstaller URI scheme after threat actors abused the App Installer web-based install mechanism to distribute malware and bypass SmartScreen and browser warnings. The company plans to revoke abused code-signing certificates, recommends updating vulnerable App Installer versions and applying Group Policy controls, and has re-enabled the protocol for select enterprise customers with explicit policy settings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.