CVE-2024-38189: Microsoft Project Remote Code Execution Vulnerability
Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file.
Other sources
Microsoft Project Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5461.1001Patch KB5002561
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38189?
CVE-2024-38189 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2024-38189?
To fix CVE-2024-38189, apply the latest security updates provided by Microsoft for affected software versions.
Which software is affected by CVE-2024-38189?
CVE-2024-38189 affects multiple Microsoft products, including Microsoft Project 2016, Office 2019, and Microsoft 365 Apps for Enterprise.
Can CVE-2024-38189 be exploited remotely?
Yes, CVE-2024-38189 can be exploited remotely through a malicious file.
What types of vulnerabilities are related to CVE-2024-38189?
CVE-2024-38189 is related to remote code execution vulnerabilities specifically within Microsoft Project.