CVE-2024-38189: Microsoft Project Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Actively Exploited
Exploitation Likelihood
Detected
Patch Tuesday
2024-Aug
Released
2024-08-13
Last Updated
2024-08-14
EPSS Score
43.66% (percentile: 97.5%)
CISA KEV
Listed — due 2024-09-03

FAQ

How could an attacker exploit this vulnerability? Exploitation requires the victim to open a malicious Microsoft Office Project file on a system where the Block macros from running in Office files from the Internet policy is disabled and VBA Macro Notification Settings are not enabled allowing the attacker to perform remote code execution. In an email attack scenario, an attacker could send the malicious file to the victim and convince them to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a malicious file designed to exploit the vulnerability. An attacker would have no way to force the victim to visit the website. Instead, an attacker would have to convince the victim to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the malicious file. Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.

Affected Products (8)

Microsoft Office

  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Project 2016 (32-bit edition)
  • Microsoft Project 2016 (64-bit edition)
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions

Security Updates (2)

Revision History

  • 2024-08-13: Information published.
  • 2024-08-14: Corrected Download links in the Security Updates table. This is an informational change only.