← Vulnerability feed

Vulnerability record · CVE-2024-38189 · published 13 August 2024

CVE-2024-38189: Microsoft Project Remote Code Execution via Improper Input Validation

Microsoft · 365 Apps

Microsoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code execution on a victim's system, and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.

8.8 CVSS 3.1 High CISA KEV since 13 Aug 2024 EPSS 8.2% · top 5.3% CWE-20 · Improper input validation
8.8CVSS 3.1 base score
8.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Microsoft Project Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityThe vulnerability is in CISA's KEV catalog, indicating active exploitation, and allows remote code execution with high impact.

What it is

Microsoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code execution on a victim's system, and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the victim's user, potentially leading to full system compromise. The CVSS vector shows high confidentiality, integrity, and availability impact.

Attack surface

The flaw is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), typically opening a malicious file or link. No authentication is needed to deliver the attack.

Exploitation

CISA added this CVE to the KEV catalog on 2024-08-13 with a remediation due date of 2024-09-03, confirming active exploitation. EPSS gives a 30-day exploitation probability of about 8.2% (94.6th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory immediately.
  • If patching is not possible, follow CISA's guidance to discontinue use of the affected product or apply vendor-provided mitigations.
  • Block or restrict opening untrusted Project files and links from external sources.
  • Enable Protected View and other Office hardening features for Project documents.
  • Monitor for and restrict execution of Project files from email and web downloads.

Detection

  • Hunt for Project file executions spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
  • Monitor for unusual network connections originating from Project or Office processes.
  • Review endpoint logs for Project documents opened from temporary internet or email attachment directories.
  • Alert on creation of suspicious files or registry changes following Project document opens.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-38189 to the Known Exploited Vulnerabilities catalog on 13 August 2024 as "Microsoft Project Remote Code Execution Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 September 2024.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-38189 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed7.8CVE-2026-21514Microsoft Word security feature bypass via untrusted inputMicrosoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Micros…KEVEPSS 1.5%analysed7.8CVE-2026-21509Microsoft Office untrusted input security feature bypassMicrosoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The …KEVEPSS 73%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2021-38646Microsoft Office Access Connectivity Engine remote code executionThe Microsoft Office Access Connectivity Engine contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being mar…KEVEPSS 8.0%analysed7.3CVE-2024-38226Microsoft Publisher security feature bypass via local attackerCVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The fla…KEVEPSS 2.7%analysed

Source: NIST National Vulnerability Database (record CVE-2024-38189), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.