ZeroHour

CVE-2024-38189

KEVmass1

Input-validation RCE in Microsoft Project via crafted project files

CISA: Microsoft Project Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
8%p95
Published
()
KEV added
AI analysis

CVE-2024-38189 is an improper input validation (CWE-20) remote code execution flaw in Microsoft Project. Triggering it requires user interaction: an attacker supplies a maliciously crafted Project file, and when a user opens it, the parsing flaw allows attacker-controlled input to execute code. Successful exploitation yields code execution in the context of the user who opened the file, with high impact to confidentiality, integrity, and availability on that endpoint. Per the CPE data, affected deployments include Project 2016 and the Project client shipped with Office 2019, Office LTSC, and Microsoft 365 Apps. The flaw was one of six zero-days Microsoft patched in its August 2024 Patch Tuesday release and was confirmed to be exploited in the wild, earning a CISA KEV listing on 2024-08-13; EPSS assigns an 8.2% 30-day exploitation probability (95th percentile), and no public PoC is known.

What to do: Apply Microsoft's August 2024 Patch Tuesday security updates for Microsoft Project/Office (covering Project 2016 and the Project client in Office 2019, Office LTSC, and Microsoft 365 Apps) immediately, per the CISA KEV required action; as an interim measure, caution users against opening Project files from untrusted sources until patched. After updating, verify that the installed Project/Office build reflects the August 2024 security updates.

Affected
Microsoft Project 2016Versions prior to Microsoft's August 2024 security updates
Microsoft Project client shipped with Microsoft 365 AppsVersions prior to Microsoft's August 2024 security updates
Microsoft Project client shipped with Office 2019Versions prior to Microsoft's August 2024 security updates
Microsoft Project client shipped with Office Long Term Servicing Channel (LTSC)Versions prior to Microsoft's August 2024 security updates
Estimated exposure
mass≈ millions of enterprise desktop installations (Project desktop is a standard tool across Microsoft's hundreds-of-millions-strong Microsoft 365/Office… — Microsoft publishes no per-product install counts, but the Office/365 commercial desktop install base is in the hundreds of millions of seats and Project desktop is commonly deployed in enterprise PMO environments, so affected installs…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Project Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Project
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, office 2019, office long term servicing channel, project 2016
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news