Protection Mechanism Failure in Microsoft Office and Microsoft Publisher - CVE-2024-38226

 

Protection Mechanism Failure in Microsoft Office and Microsoft Publisher - CVE-2024-38226

Published: September 10, 2024


Vulnerability identifier: #VU97016
CSH Severity: Critical
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38226
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. An attacker can trick the victim into opening a specially crafted file, bypass Office macro policies restrictions and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Microsoft Office
Microsoft Publisher

How to mitigate CVE-2024-38226

Install updates from vendor's website.

Microsoft Office - update to 16.0.5465.1001
Microsoft Publisher - update to 16.0.5465.1001

External References

Related Security Bulletins