CVE-2024-38189HighCVSS 8.8

Microsoft Project Remote Code Execution Vulnerability

Published
August 13, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? Exploitation requires the victim to open a malicious Microsoft Office Project file on a system where the Block macros from running in Office files from the Internet policy is disabled and VBA Macro Notification Settings are not enabled allowing the attacker to perform remote code execution. In an email attack scenario, an attacker could send the malicious file to the victim and convince them to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a malicious file designed to exploit the vulnerability. An attacker would have no way to force the victim to visit the website. Instead, an attacker would have to convince the victim to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the malicious file.

Is the Preview Pane an attack vector for this vulnerability? No, the Preview Pane is not an attack vector.

🎯 Affected products8

  • Microsoft 365 Apps for Enterprise for 32-bit Systems
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft Office 2019 for 32-bit editions
  • Microsoft Office 2019 for 64-bit editions
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft Project 2016 (32-bit edition)
  • Microsoft Project 2016 (64-bit edition)

✅ Remediation

KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KB5002561 (Security Update) — fixed build 16.0.5461.1001

🔗 References (5)