Protection Mechanism Failure in Microsoft Office and Microsoft Publisher - CVE-2024-38226
Published: September 10, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. An attacker can trick the victim into opening a specially crafted file, bypass Office macro policies restrictions and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Microsoft Publisher
How to mitigate CVE-2024-38226
Microsoft Publisher - update to 16.0.5465.1001