CVE-2024-38226: Microsoft Publisher Protection Mechanism Failure Vulnerability
Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files.
Other sources
Microsoft Publisher Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5465.1001Patch KB5002566 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade
Microsoft Publisher 2010to a version that resolves this vulnerability.Fixed in 16.0.5465.1001Patch KB5002566
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38226?
CVE-2024-38226 has a critical severity rating due to its potential to bypass security mechanisms in Microsoft Publisher.
How do I fix CVE-2024-38226?
To fix CVE-2024-38226, update Microsoft Publisher and Office to the latest security versions provided by Microsoft.
Which versions of Microsoft Publisher are affected by CVE-2024-38226?
CVE-2024-38226 affects Microsoft Publisher 2016, 2019, and 2021 across both 32-bit and 64-bit editions.
Can CVE-2024-38226 allow malicious macros to run?
Yes, CVE-2024-38226 can allow attackers to bypass Office macro policies, potentially enabling malicious macros to execute.
What type of vulnerability is CVE-2024-38226?
CVE-2024-38226 is classified as a security feature bypass vulnerability.