Headline
CVE-2024-38177: Windows App Installer Spoofing Vulnerability
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The attacker must convince a user to call Windows App Installer with a specially crafted malicious winget file.