Vulnerability record · CVE-2024-38189 · published 13 August 2024
CVE-2024-38189: Microsoft Project Remote Code Execution via Improper Input Validation
Microsoft · 365 Apps
Microsoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code execution on a victim's system, and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.
Description
Microsoft Project Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is in CISA's KEV catalog, indicating active exploitation, and allows remote code execution with high impact.
What it is
Microsoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code execution on a victim's system, and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the victim's user, potentially leading to full system compromise. The CVSS vector shows high confidentiality, integrity, and availability impact.
Attack surface
The flaw is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), typically opening a malicious file or link. No authentication is needed to deliver the attack.
Exploitation
CISA added this CVE to the KEV catalog on 2024-08-13 with a remediation due date of 2024-09-03, confirming active exploitation. EPSS gives a 30-day exploitation probability of about 8.2% (94.6th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory immediately.
- If patching is not possible, follow CISA's guidance to discontinue use of the affected product or apply vendor-provided mitigations.
- Block or restrict opening untrusted Project files and links from external sources.
- Enable Protected View and other Office hardening features for Project documents.
- Monitor for and restrict execution of Project files from email and web downloads.
Detection
- Hunt for Project file executions spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Monitor for unusual network connections originating from Project or Office processes.
- Review endpoint logs for Project documents opened from temporary internet or email attachment directories.
- Alert on creation of suspicious files or registry changes following Project document opens.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-38189 to the Known Exploited Vulnerabilities catalog on 13 August 2024 as "Microsoft Project Remote Code Execution Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 September 2024.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38189 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38189 | US Government Resource |
Track CVE-2024-38189 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-38189), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.