CVE-2021-4389
✓ Confirmed 0-Day
Triaged: March 20, 2026
1 article
EPSS Score
Source: FIRST.org · 2026-05-24
0.14%
probability
This CVE has a 0.14% probability
of being exploited in the next 30 days.
0%
Top 33.3th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Microsoft fixes Windows AppX Installer zero-day used by Emotet
BleepingComputer
Dec 14, 2021
Signal Intelligence
Confidence
75%
EPSS
0.14%
Mentions
1
Last Seen
Dec 14, 2021
CNA Information
Analyst Note
Article explicitly identifies CVE-2021-4389 as a 'zero-day used by Emotet' in the title, with Microsoft patching it. The 2021 CVE year and active Emotet exploitation in the wild strongly support zero-day classification, though the truncated excerpt limits full timeline verification of patch-vs-exploitation timing.
Triage Info
Decided atMar 20, 2026