Node.js MSI install fails on Windows 11 due to Smart App Control blocking custom action DLL (Error 1723)
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 122k
- Forks
- 37.3k
- Avg merge
- 4d 2h
- Merged PRs (30d)
- 283
Description
Version
24.15.0
Platform
Microsoft Windows NT 10.0.26200.0 x64
Subsystem
No response
What steps will reproduce the bug?
- Open an elevated PowerShell session.
- Run:
Start-Process winget.exe -ArgumentList 'install --id OpenJS.NodeJS.LTS -e --accept-package-agreements --accept-source-agreements' -Verb RunAs -Wait - Wait for the installer to start.
- Observe Windows Security notification:
- "This app has been blocked partly"
- "Windows Installer may not work correctly because it could not verify what MSI2C91.tmp was trying to load"
- Installation fails.
How often does it reproduce? Is there a required condition?
Always, with Smart App Control (SAC) enabled on Windows 11.
What is the expected behavior? Why is that the expected behavior?
winget install --id OpenJS.NodeJS.LTS should complete successfully on Windows 11 with SAC enabled.
What do you see instead?
Installation fails. Windows Security / SAC blocks a temporary DLL loaded by Windows Installer during a custom action. The main MSI package is signed, but installation fails with Error 1723.
Additional information
Application log / MsiInstaller:
Product: Node.js -- Error 1723. There is a problem with this Windows Installer package. A DLL required for this install to complete could not be run.
Action SetInstallScope, entry: SetInstallScope, library: C:\Windows\Installer\MSI2C91.tmp
CodeIntegrity / Operational:
Code Integrity determined that a process (msiexec.exe) attempted to load C:\Windows\Installer\MSI2C91.tmp that did not meet the Enterprise signing level requirements or violated code integrity policy
Smart App Control Block Details
- MSI payload downloaded by winget is signed and valid (
Get-AuthenticodeSignaturereportsStatus : Valid). - Not caused by winget arguments, GPO, MDM, or domain-join policy.
- Blocked file:
C:\Windows\Installer\MSI2C91.tmploaded bymsiexec.exe. - SmartAppControlState: On
- CI\Policy: VerifiedAndReputablePolicyState = 1
- Block occurs when
msiexec.exeloads the temporary DLL for custom actionSetInstallScope.
[!NOTE]
The Node.js MSI contains a custom action namedSetInstallScope. SAC appears to block the temporary custom-action DLL generated during installation, not the signed MSI package itself. If this is expected, a clearer error message identifying the blocked install step and affected component would help troubleshooting.
[!TIP]
Turn SAC off to work around.
You can turn it on later manually without a clean installation (the former documentation is obsolete if you have gotten recent Windows updates).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the Windows 11 installation with Smart App Control enabled and trace the MSI custom action named SetInstallScope. Review how the Node.js MSI packages and loads its custom-action DLL, then verify the installation completes without Error 1723 or produces a clearer diagnostic for the blocked component.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- operating-systems, release
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100