EXPOSURES › CVE-2024-38189
CVE-2024-38189
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Project allows remote code execution via a malicious file, enabling attackers to compromise DIB systems.
This vulnerability allows remote code execution through a malicious file in Microsoft Project, posing a significant risk to DIB organizations using the software. The fact that it is actively exploited in the KEV list indicates it is being targeted by threat actors, necessitating immediate patching to prevent unauthorized access and data exfiltration.
Shame score — While the vulnerability is serious and actively exploited, it is a standard remote code execution flaw in a widely used application rather than a unique or negligent failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |