CVE-2026-23656: Windows App Installer Spoofing Vulnerability
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.
Other sources
Windows App Installer Spoofing Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23656?
CVE-2026-23656 is considered to be a high severity vulnerability due to its potential for unauthorized spoofing attacks.
How do I fix CVE-2026-23656?
To mitigate CVE-2026-23656, users should update to the latest version of Windows App Client for Windows Desktop as provided in the patch.
Who is affected by CVE-2026-23656?
CVE-2026-23656 affects users of Microsoft Windows App Client for Windows Desktop versions prior to 2.0.964.0.
What type of vulnerability is CVE-2026-23656?
CVE-2026-23656 is a spoofing vulnerability caused by insufficient verification of data authenticity.
Can CVE-2026-23656 be exploited remotely?
Yes, CVE-2026-23656 can be exploited remotely, allowing attackers to spoof data over a network.