Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-23656

Опубликовано: 10 мар. 2026
Источник: msrc
CVSS3: 5.9
EPSS Низкий

Описание

Windows App Installer Spoofing Vulnerability

Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Exploitation requires the attacker to first gain the ability to intercept or influence update‑related network communications. This depends on environment‑specific conditions and preparatory actions that are outside the attacker’s direct control, making the exploit difficult to perform reliably.

Обновления

ПродуктСтатьяОбновление
Windows App Client for Windows Desktop

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

EPSS

Процентиль: 6%
0.00024
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
17 дней назад

Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.9
github
17 дней назад

Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.9
fstec
17 дней назад

Уязвимость клиента удаленного рабочего стола Windows App Client (ранее - Remote Desktop Client), связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 6%
0.00024
Низкий

5.9 Medium

CVSS3