Microsoft patches dangerous 'zero-day' Windows flaws — what to do now

Windows 10 logo
(Image credit: Microsoft)

Update your home PCs, Windows users, because there's a nasty security flaw out there that's already being used in online attacks. Microsoft pushed out a fix for the vulnerability in yesterday's (Dec. 14) round of monthly Patch Tuesday updates.

The "zero-day" flaw, catalogued as CVE-2021-43890, is apparently being used by cybercriminals to spread malware that steals sensitive information from PCs and tries to get you to call fake tech-support lines. Windows 10 and Windows 11 are equally vulnerable.

The flaw stems from an issue with with the Windows App Installer tool, which can also be downloaded from the online Microsoft Store.

"Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader," said the security advisory released about the flaw. 

"An attacker could craft a malicious attachment to be used in phishing campaigns," the advisory added. "The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."

How to protect yourself

That last sentence highlights one of the least-known, but most effective, security safeguards that Windows users can implement. If you set up your regular "daily driver" Windows account as a "limited user" that can't install or modify software, you are at much less risk of your computer being seriously hacked. 

Your administrative account can stay dormant. Even when you do need to update things, you can just use the admin account's password to get things done without having to fully log into it.

Anyhow, to update your Windows machine, click the Windows icon on the bottom left of the screen (or the bottom center if you're running Windows 11), then the gear icon in the pop-up menu. This brings you to the Windows Settings screen; click Update and Security, then click the Check for Updates button. 

If you want to have updates installed automatically, then click Advanced Options while you're on that page and toggle the appropriate entry.

Microsoft patched 66 other flaws in its various software packages yesterday, including five other vulnerabilities that were also classified as zero-days because word got out about them before fixes were ready. The flaw described in detail above is the only one of the bunch that we know is already being exploited.

One of the most serious flaws that's not a zero-day involves remote code execution — that's hacking over the internet to you and me — in Microsoft Office. While the App Installer flaw has a severity score of 7.1 out of 10, this one rates a 9.6. 

Microsoft isn't providing many details about this flaw, presumably because the software giant doesn't want anyone figuring out how to exploit it before most people have had a chance to install the patch.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
A laptop on a windowsill in the middle of a Windows update
Microsoft is ending support for Windows 10 soon — 5 ways to make sure your PC is secure
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now