peter bassill · operator
$ cve CVE-2024-38226 JSON

CVE-2024-38226 KEV

7.3
HIGH · CVSS 3.1 · EPSS 2.7% (pctl 85)

Patch first

On CISA KEV — known exploited in the wild, due 2024-10-01.

Description

Microsoft Publisher Security Feature Bypass Vulnerability

Scoring

CVSS7.3 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS2.67% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-693
On CISA KEVyes — remediate by 2024-10-01
Public exploitnone known
Published2024-09-10
Last modified2026-08-10

CISA KEV

NameMicrosoft Publisher Protection Mechanism Failure Vulnerability
Added2024-09-10
Due2024-10-01
Vendor / productMicrosoft / Publisher
Ransomware usenone reported

Affected (3)

VendorProduct
microsoftoffice 2019
microsoftoffice long term servicing channel
microsoftpublisher

References

→ the Explorer  ·  watch your stack  ·  NVD