Junglewise Threat Intelligence

CVE-2024-38189: Microsoft Project Remote Code Execution Vulnerability

CVE-2024-38189 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-08-13

Technologies: Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Project contains a remote code execution vulnerability due to improper input validation. An attacker can exploit this by convincing a user to open a specially crafted malicious file, leading to full system compromise.

Affected products

  • Microsoft Project 2016 up to (excluding) 16.0.5461.1001
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft 365 Apps for Enterprise

Timeline

  • 2024-08-13: disclosed
  • 2024-08-13: patched
  • 2024-08-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-08-13: exploited: Reported as exploited in the wild at time of publication.