ZeroHour

CVE-2024-38226

KEVmass

Actively Exploited Security Feature Bypass in Microsoft Publisher

CISA: Microsoft Publisher Protection Mechanism Failure Vulnerability

CVSS 3.1
7.3 high
EPSS
3%p85
Published
()
KEV added
AI analysis

CVE-2024-38226 is a security feature bypass (protection mechanism failure, CWE-693) in Microsoft Publisher, rated 7.3 High with a local attack vector, low privileges required, and user interaction required. An attacker triggers it by convincing a user to open a maliciously crafted Publisher file, which defeats Publisher's built-in protection mechanism, allowing the attacker's content to bypass the expected security checks, with high impact rated for confidentiality, integrity, and availability. Users of Publisher as shipped in Microsoft Office 2019 and Microsoft Office Long Term Servicing Channel (LTSC) are affected. The flaw was patched in Microsoft's September 2024 Patch Tuesday, counted among the four actively exploited Microsoft zero-days that month, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-10, confirming exploitation in the wild; ransomware use is listed as unknown.

What to do: Apply the September 2024 Microsoft security updates for Office 2019/LTSC (Publisher) across all endpoints, prioritizing systems with Publisher installed, per the vendor's instructions or the CISA KEV required action. Until patched, warn users to exercise caution with .pub files from untrusted sources, since exploitation requires opening a crafted file. Confirm no Publisher clients remain on outdated builds after deployment.

Affected
Microsoft Publisher (shipped with Microsoft Office 2019)
Microsoft Publisher (shipped with Microsoft Office Long Term Servicing Channel, LTSC)
Estimated exposure
massmillions of users (Publisher is bundled with enterprise perpetual-license Office 2019/LTSC suites; no precise public install counts for these channels) — Office 2019 and Office LTSC are widely deployed in enterprises and government, and Publisher is included in their professional editions, implying an installed base plausibly above one million, though exact Publisher user counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Publisher Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Publisher
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
office 2019, office long term servicing channel, publisher
Weakness
CWE-693
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news