Spoofing Vulnerability in Windows App Installer Affects Microsoft Products
CVE-2026-23656
5.9MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-23656?
A spoofing vulnerability exists in the Windows App Installer due to insufficient verification of data authenticity. This weakness can allow an unauthorized attacker to execute spoofing attacks over the network, potentially compromising the integrity of data transfers and user trust. Users are advised to monitor updates from Microsoft and apply relevant patches to mitigate any risks associated with this vulnerability.
Affected Version(s)
Windows App Client for Windows Desktop 1.00 < 2.0.964