{"id":44161,"date":"2021-11-26T10:24:05","date_gmt":"2021-11-26T10:24:05","guid":{"rendered":"http:\/\/f80232c2-beaf-438b-8f39-c93271f9f46e"},"modified":"2021-11-26T10:24:05","modified_gmt":"2021-11-26T10:24:05","slug":"hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/","title":{"rendered":"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\" class=\"ff-og-image-inserted\"><\/div>\n<p>Hackers have already created malware in a bid to exploit an elevation of privilege vulnerability in Microsoft&#8217;s Windows Installer.<\/p>\n<p>Microsoft released a patch for <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-41379\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">CVE-2021-41379<\/a>, an elevation of privilege flaw in the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/msi\/windows-installer-portal\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Windows Installer component<\/a> for enterprise application deployment. It had an &#8220;important&#8221; rating and a severity score of just 5.5 out of 10.&nbsp;<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"> <span class=\"int\">Windows 11<\/span> <\/h3>\n<\/p><\/div>\n<p>It wasn&#8217;t actively being exploited at the time, but it is now, according to Cisco&#8217;s Talos malware researchers. And Cisco reports that the bug can be exploited even on systems with the November patch to give an attacker administrator-level privileges.&nbsp;<\/p>\n<p><strong>SEE: <\/strong><a href=\"https:\/\/www.zdnet.com\/article\/windows-11-faq-heres-everything-you-need-to-know\/\"><strong>Windows 11 FAQ: Our upgrade guide and everything else you need to know<\/strong><\/a><\/p>\n<p>This, however, contradicts <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-41379\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">Microsoft&#8217;s assessment that<\/a>&nbsp;an attacker would only be able to delete targeted files on a system and would not gain privileges to view or modify file contents.<\/p>\n<p>&#8220;This vulnerability allows an attacker with a limited user account to elevate their privileges to become an administrator,&#8221; <a href=\"https:\/\/blog.talosintelligence.com\/2021\/11\/attackers-exploiting-zero-day.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">explains Jaeson Schultz at Cisco Talos<\/a>.&nbsp;<\/p>\n<p>&#8220;This vulnerability affects every version of Microsoft Windows, including fully patched Windows 11 and Server 2022. Talos has already detected malware samples in the wild that are attempting to take advantage of this vulnerability.&#8221;<\/p>\n<section class=\"sharethrough-top placeholder\"> <\/section>\n<p>Abdelhamid Naceri, the researcher who reported CVE-2021-41379 to Microsoft, tested patched systems and on November 22 <a href=\"https:\/\/github.com\/klinix5\/InstallerFileTakeOver\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">published proof-of-concept exploit code on GitHub<\/a>, which shows that it works despite Microsoft&#8217;s fixes. It also works on Server versions of affected Windows, including Windows Server 2022.&nbsp;<\/p>\n<p>&#8220;The code Naceri released leverages the discretionary access control list (DACL) for Microsoft Edge Elevation Service to replace any executable file on the system with an MSI file, allowing an attacker to run code as an administrator,&#8221; writes Cisco&#8217;s Shultz.<\/p>\n<p><strong>SEE: <\/strong><a href=\"https:\/\/www.zdnet.com\/article\/college-for-cyber-criminals-dark-web-crooks-are-teaching-courses-on-how-to-build-botnets\/#link=%7B%22role%22:%22standard%22,%22href%22:%22https:\/\/www.zdnet.com\/article\/college-for-cyber-criminals-dark-web-crooks-are-teaching-courses-on-how-to-build-botnets\/%22,%22target%22:%22_blank%22,%22absolute%22:%22%22,%22linkText%22:%22Dark%20web%20crooks%20are%20now%20teaching%20courses%20on%20how%20to%20build%20botnets%22%7D\"><strong>Dark web crooks are now teaching courses on how to build botnets<\/strong><\/a><\/p>\n<p>He adds that this &#8220;functional proof-of-concept exploit code will certainly drive additional abuse of this vulnerability.&#8221;&nbsp;<\/p>\n<p>Naceri says there is no workaround for this bug other than another patch from Microsoft.&nbsp;<\/p>\n<p>&#8220;Due to the complexity of this vulnerability, any attempt to patch the binary directly will break Windows Installer. So you&#8217;d better wait and see how\/if Microsoft will screw the patch up again,&#8221; Naceri said. Microsoft is yet to acknowledge Naceri&#8217;s new proof of concept and has not yet said whether it will issue a patch for it.&nbsp;<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Flaw can be exploited to give an attacker administrator rights on a compromised system, despite efforts to fix the problem.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-44161","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackers are targeting this Microsoft Windows Installer flaw, say security researchers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-26T10:24:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers\",\"datePublished\":\"2021-11-26T10:24:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/\"},\"wordCount\":407,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/2a102be54d9ddd3c0248d626ef37c0849594dc76\\\/2021\\\/10\\\/20\\\/198f613b-750c-4aef-bb40-ac9098fb74d4\\\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/\",\"name\":\"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/2a102be54d9ddd3c0248d626ef37c0849594dc76\\\/2021\\\/10\\\/20\\\/198f613b-750c-4aef-bb40-ac9098fb74d4\\\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"datePublished\":\"2021-11-26T10:24:05+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/2a102be54d9ddd3c0248d626ef37c0849594dc76\\\/2021\\\/10\\\/20\\\/198f613b-750c-4aef-bb40-ac9098fb74d4\\\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/2a102be54d9ddd3c0248d626ef37c0849594dc76\\\/2021\\\/10\\\/20\\\/198f613b-750c-4aef-bb40-ac9098fb74d4\\\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/","og_locale":"en_US","og_type":"article","og_title":"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-11-26T10:24:05+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers","datePublished":"2021-11-26T10:24:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/"},"wordCount":407,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/","url":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/","name":"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","datePublished":"2021-11-26T10:24:05+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/2a102be54d9ddd3c0248d626ef37c0849594dc76\/2021\/10\/20\/198f613b-750c-4aef-bb40-ac9098fb74d4\/shutterstock-1692847237.jpg?width=770&amp;height=578&amp;fit=crop&amp;auto=webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hackers-are-targeting-this-microsoft-windows-installer-flaw-say-security-researchers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Hackers are targeting this Microsoft Windows Installer flaw, say security researchers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=44161"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44161\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=44161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=44161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=44161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}