Executive brief
Microsoft Publisher contains a protection mechanism failure vulnerability that allows an attacker to bypass Office macro policies. This flaw enables the execution of untrusted or malicious files that would otherwise be blocked by security features.
Affected products
- Microsoft Publisher 2016 x86, x64
- Microsoft Office 2019 x86, x64
- Microsoft Office LTSC 2021 x86, x64
Timeline
- 2024-09-10: disclosed
- 2024-09-10: patched
- 2024-09-10: kev added: Added to CISA KEV catalog due to active exploitation.
- 2024-09-10: exploited: Reported as exploited in the wild at the time of disclosure.