← Vulnerability feed

Vulnerability record · CVE-2024-38226 · published 10 September 2024

CVE-2024-38226: Microsoft Publisher security feature bypass via local attacker

Microsoft · Office 2019

CVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The flaw lets an attacker defeat a protection mechanism, which matters because Microsoft and CISA both treat it as exploited in the wild. The record gives no detail on the specific protection bypassed or the vulnerable code path.

7.3 CVSS 3.1 High CISA KEV since 10 Sep 2024 EPSS 2.7% · top 14.8% CWE-693 · CWE-693
7.3CVSS 3.1 base score
2.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
10 Aug 2026Last modified by NVD

Description

Microsoft Publisher Security Feature Bypass Vulnerability

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is confirmed exploited in CISA KEV with a high CVSS of 7.3, but requires local access and user interaction, limiting mass exploitation.

What it is

CVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The flaw lets an attacker defeat a protection mechanism, which matters because Microsoft and CISA both treat it as exploited in the wild. The record gives no detail on the specific protection bypassed or the vulnerable code path.

Impact

An attacker can bypass a Publisher security feature, gaining high confidentiality, integrity and availability impact on the local system. The exact actions enabled are not described in the record.

Attack surface

The CVSS vector is local (AV:L) with low privileges (PR:L) and required user interaction (UI:R), so an attacker needs local access and must convince a user to open or act on a crafted Publisher file. No remote or unauthenticated path is indicated.

Exploitation

CVE-2024-38226 is listed in CISA KEV with a due date of 2024-10-01, confirming known exploitation, though EPSS 30-day probability is low at 0.02667 (84.98th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Microsoft security update for CVE-2024-38226 immediately; CISA's required action is to apply vendor mitigations or discontinue use of the product.
  • If patching cannot be completed, restrict or block use of Microsoft Publisher and opening of untrusted Publisher files.
  • Enforce least privilege so users do not operate with administrative rights, reducing the local attack surface.
  • Block Publisher file attachments and downloads from external or untrusted sources at email and web gateways.
  • Track KEV remediation to the 2024-10-01 due date and verify patch status across Office 2019 and LTSC installs.

Detection

  • Monitor for Publisher (MSPUB.EXE) spawning unusual child processes or writing to sensitive locations.
  • Alert on Publisher documents opened from email attachments, downloads or temporary directories.
  • Audit endpoints for missing Microsoft Office updates matching CVE-2024-38226 and report unpatched hosts.
  • Review process creation and file write telemetry around Publisher sessions for signs of protection bypass.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-38226 to the Known Exploited Vulnerabilities catalog on 10 September 2024 as "Microsoft Publisher Protection Mechanism Failure Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 1 October 2024.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-38226 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed7.8CVE-2026-21514Microsoft Word security feature bypass via untrusted inputMicrosoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Micros…KEVEPSS 1.5%analysed7.8CVE-2026-21509Microsoft Office untrusted input security feature bypassMicrosoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The …KEVEPSS 73%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed

Source: NIST National Vulnerability Database (record CVE-2024-38226), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.