Microsoft kills off Windows app installation from the web, again
- Reference: 1704326564
- News link: https://www.theregister.co.uk/2024/01/04/microsoft_windows_app_installation/
- Source link:
The move came just before Christmas, and seemingly mimicked issues first reported in [1]December 2021 , to address a Windows AppX Installer vulnerability ( [2]CVE-2021-43890 ) in which an attacker could spoof App Installer into installing malicious software.
Microsoft re-enabled the protocol, known as the ms-appinstaller URI scheme, [3]on August 5, 2022 , with the release of Windows 11 Insider Preview Build 25147. It made the protocol available to some enterprise customers who chose to use it via the Local Group Policy Editor.
[4]
The ms-appinstaller URI scheme allows the [5]MSIX package installer to install Windows apps [6]from a web page using the local App Installer application. Doing so allows installation without the need for local storage. This has proven to be a popular feature, according to Microsoft.
[7]
[8]
Alas, as the Microsoft Threat Intelligence group [9]noted last week, miscreants have been abusing the ms-appinstaller URI scheme to distribute malware. It appears that the protocol provided a way around Microsoft's security checks.
"Threat actors have likely chosen the ms-appinstaller protocol handler vector because it can bypass mechanisms designed to help keep users safe from malware, such as Microsoft Defender SmartScreen and built-in browser warnings for downloads of executable file formats," Redmond explained.
[10]Microsoft prepares Visual Studio 2013 for retirement
[11]Windows boss takes on taskbar turmoil, pledges to 'make Start menu great again'
[12]Windows 11 unable to escape the shadow of Windows 10
[13]Microsoft issues deadline for end of Windows 10 support – it's pay to play for security
Microsoft had relied on developers having to sign their app packages with "a third party paid certificate from a trusted certification authority," but evidently it put too much trust in such authorities.
Following its decision to disable ms-appinstaller by default last week (in App Installer version 1.21.3421.0 or higher), Redmond announced it is working with certificate authorities "to revoke the abused code signing certificates utilized by malware samples we have identified."
[14]
Customers who have EnableMSAppInstallerProtocol group policy set to "Not Configured" (blank) or "Enabled" and are also using vulnerable versions of App Installer – from v1.18.2691 up until v1.21.3421, as well as Windows OS updates between October 2022 and March 2023 – are advised to update App Installer and to set the desired policy.
For enterprise customers, pushing out a network-wide policy change may take some effort. And for those who rely on web-based installation as an app distribution channel, the consequence is a bit more friction for downloading and installation after proper checks.
Microsoft did not respond to a request for comment. ®
Get our [15]Tech Resources
[1] https://github.com/MicrosoftDocs/msix-docs/commit/3c3ab6d2df2e373590fef21dba6d468f58a11343
[2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43890
[3] https://techcommunity.microsoft.com/t5/windows-it-pro-blog/disabling-the-msix-ms-appinstaller-protocol-handler/ba-p/3119479
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZY7eWT@GgReI3ybYSbonwAAAUg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://learn.microsoft.com/en-us/windows/msix/overview
[6] https://learn.microsoft.com/en-us/windows/msix/app-installer/installing-windows10-apps-web
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZY7eWT@GgReI3ybYSbonwAAAUg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZY7eWT@GgReI3ybYSbonwAAAUg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.microsoft.com/en-us/security/blog/2023/12/28/financially-motivated-threat-actors-misusing-app-installer/
[10] https://www.theregister.com/2024/01/03/visual_studio_2013_support/
[11] https://www.theregister.com/2024/01/03/windows_11_start_great_again/
[12] https://www.theregister.com/2024/01/02/windows_11_unable_to_escape/
[13] https://www.theregister.com/2023/12/06/microsoft_windows_10_security/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZY7eWT@GgReI3ybYSbonwAAAUg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
"from a trusted certification authority"
Would be nice to know who they were, so I could remove them from my certificate repository.
Are they honestly not going to get any blowback from this?
"Yeah, we vetted 'em... their check cleared."
In other news...
Local government decrees that the front door on every house must be left unlocked because a couple of the councillors' close friends were expecting visitors and couldn't be bothered getting off their arses to answer the doorbell.
Why is it always the lowest common denominator that gets catered to? The IT world was a much better place when it was inhabited exclusively by eggheads; nobody back then prioritised changing the colour of a UI element over improving its functionality.
Maybe M$ should simply have an "I'm an idiot" tickbox at installation time, the result of which Windows can use to determine whether such "conveniences" are enabled or disabled by default.
How Come Microsoft Can’t Get It To Work?
Linux distros have been doing signed package repositories for years, with good results. Why can’t Microsoft manage the same? Is it because proprietary software developers can’t be trusted?
This has proven to be a popular feature, according to Microsoft
Popular with who? Microsoft? They're the ones constantly installing apps I never asked for all over my enterprise.
M$ always leaves barn door open for "business"
On one hand how nice of M$ to not require signing apps by their own CA (for a fee of course), on the other hand how the hell they allowed zero touch installs of all appx packages instead of restricting them to ones signed by specific CA (as defined by a group policy pushed by a business that cared for this sort of app deployments)?
To be fair to Microsoft…
…no-one, absolutely no-one , could have foreseen that a mechanism for allowing arbitrary web pages to silently and automatically install applications on user PCs might be abused. That would call into question the integrity of the world’s CAs, and if you can’t trust CAs, who can you trust?
Oh, sorry, forgot my tags there.