Junglewise Threat Intelligence

CVE-2024-38226: Microsoft Publisher Protection Mechanism Failure Vulnerability

CVE-2024-38226 · Severity: critical · CVSS 7.3 · Exploited in the wild · Published 2024-09-10

Technologies: Microsoft Office 2019, Microsoft Office LTSC 2021. Vendors: Microsoft.

Executive brief

Microsoft Publisher contains a protection mechanism failure vulnerability that allows an attacker to bypass Office macro policies. This flaw enables the execution of untrusted or malicious files that would otherwise be blocked by security features.

Affected products

  • Microsoft Publisher 2016 x86, x64
  • Microsoft Office 2019 x86, x64
  • Microsoft Office LTSC 2021 x86, x64

Timeline

  • 2024-09-10: disclosed
  • 2024-09-10: patched
  • 2024-09-10: kev added: Added to CISA KEV catalog due to active exploitation.
  • 2024-09-10: exploited: Reported as exploited in the wild at the time of disclosure.