Executive brief
Microsoft Project contains a remote code execution vulnerability due to improper input validation. An attacker can exploit this by convincing a user to open a specially crafted malicious file, leading to full system compromise.
Affected products
- Microsoft Project 2016 up to (excluding) 16.0.5461.1001
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft 365 Apps for Enterprise
Timeline
- 2024-08-13: disclosed
- 2024-08-13: patched
- 2024-08-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-08-13: exploited: Reported as exploited in the wild at time of publication.