cbcvebase.
CVE-2024-38226
published 2024-09-10

CVE-2024-38226: Microsoft Publisher Security Feature Bypass Vulnerability

PriorityP179high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-01
Exploited in the wild
EPSS
2.67%
84.1th percentile
Microsoft Publisher Security Feature Bypass Vulnerability

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_publisher_2016>= 16.0.0 < 16.0.5465.100116.0.5465.1001
microsoftoffice_long_term_servicing_channel
microsoftpublisher
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_office_ltsc_2021_for_32-bit_editions
msrcmicrosoft_office_ltsc_2021_for_64-bit_editions
msrcmicrosoft_publisher_2016

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-38226 is exploited in the wild via a specially crafted Microsoft Publisher file that bypasses Office macro policies (Mark of the Web / macro execution controls). Detection should focus on Publisher files opened from web-downloaded sources that execute macros despite policy blocks.
  • The attack vector requires social engineering to lure a victim into downloading and opening a specially crafted Publisher file from a website, triggering a local attack. Monitor for Publisher (.pub) files downloaded from the internet being opened and spawning child processes or executing macros.
  • The Preview Pane is NOT an attack vector for CVE-2024-38226; exploitation requires the victim to fully open the malicious Publisher file.
  • CVE-2024-38226 is confirmed actively exploited (Exploit Status: Exploited:Yes). Prioritize detection on endpoints running unpatched Microsoft Publisher versions prior to the September 2024 Click-to-Run update.
  • ·The vulnerability is a protection mechanism failure — it bypasses Office macro policies. Existing macro-blocking Group Policy or WDAC rules may be silently circumvented on unpatched Publisher installs, meaning policy enforcement logs alone are insufficient to confirm safety.
  • ·Remediation is delivered via Click-to-Run update mechanism, not a traditional MSI/Windows Update patch. Environments that restrict or delay Click-to-Run updates may remain exposed even if Windows Update is current.

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vulncheck7.3HIGH
cisa7.3HIGH
vendor_msrc7.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.