Version 1.29.290.0 - does it address CVE-2026-68821? #6472
|
The store released an unlisted version of 1.29.290.0 . I see no information on this build in here. I am wondering if this version addresses CVE-2026-68821 ? I am a little wary to push out a preview version of Appinstaller to all of my machines, as suggested by the MSRC... If there is any information on how we should proceed to address this CVE, it would be appreciated. |
Replies: 4 comments 7 replies
|
The provided package didn't work so I'm still below 1.30.xxx. I've found nothing that works to update it so for now, this is a false flag for me. |
|
Looking at #6332 and it's: "Fix configuration elevation validation for standard flow (1.29) by JohnMcPMS" It looks like the fix from 1.30.80 was backported to the 1.29.* branch. MS page https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821 links a "Security update" Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle that has the 1.29.280 manifest inside Yet the build number on the page says 1.30.80 which is a preview. My suggestion is - Installing 1.29.280 (which I've noticed some of the systems already have) and wait for the official feedback from MS. |
|
I'll give that a go and perform a remediation scan. Fingers crossed. Just
not certain the scan is looking beyond the version number.
…On Wed, Aug 19, 2026, 20:03 SelfMan ***@***.***> wrote:
Looking at
#6332 <#6332>
and it's: "Fix configuration elevation validation for standard flow (1.29)
by JohnMcPMS <https://github.com/JohnMcPMS>"
It looks like the fix from 1.30.80 was backported to the 1.29.* branch.
MS page
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821
links a "Security update"
Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle that has the
1.29.280 manifest inside
AppxBundleManifest.xml
<https://github.com/user-attachments/files/31244809/AppxBundleManifest.xml>
Yet the build number on the page says 1.30.80 which is a preview.
My suggestion is - Installing 1.29.280 (which I've noticed some of the
systems already have) and wait for the official feedback from MS.
—
Reply to this email directly, view it on GitHub
<#6472?email_source=notifications&email_token=CL7VHFYA52K77JDNDSMVFUL5KZE6HA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBQHA3DCOBVUZZGKYLTN5XKOY3PNVWWK3TUUVSXMZLOOSWGM33PORSXEX3DNRUWG2Y#discussioncomment-18086185>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/CL7VHF6Y5LD5LW2WFPZ6YMD5KZE6HAVCNFSNUABIKJSXA33TNF2G64TZHMYTSNZSG42TCMZQHNCGS43DOVZXG2LPNY5TCMBWGQ2DANBQUF3AE>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/CL7VHF7SHOSA5XFGGW2XTZD5KZE6HA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBQHA3DCOBVUZZGKYLTN5XKOY3PNVWWK3TUUVSXMZLOOSVGM33PORSXEX3JN5ZQ>
and Android
<https://github.com/notifications/mobile/android/CL7VHF5K25DWJDUMGIX6JAL5KZE6HA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBQHA3DCOBVUZZGKYLTN5XKOY3PNVWWK3TUUVSXMZLOOSXGM33PORSXEX3BNZSHE33JMQ>.
Download it today!
You are receiving this because you commented.Message ID:
***@***.***>
|
|
I believe there is some confusion here. It looks like we need to get the CVE listing updated. This is the stable version to address the vulnerability: |
I believe there is some confusion here. It looks like we need to get the CVE listing updated.
This is the stable version to address the vulnerability: