Vulnerability record · CVE-2024-38226 · published 10 September 2024
CVE-2024-38226: Microsoft Publisher security feature bypass via local attacker
Microsoft · Office 2019
CVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The flaw lets an attacker defeat a protection mechanism, which matters because Microsoft and CISA both treat it as exploited in the wild. The record gives no detail on the specific protection bypassed or the vulnerable code path.
Description
Microsoft Publisher Security Feature Bypass Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is confirmed exploited in CISA KEV with a high CVSS of 7.3, but requires local access and user interaction, limiting mass exploitation.
What it is
CVE-2024-38226 is a security feature bypass in Microsoft Publisher, affecting Office 2019, Office Long Term Servicing Channel, and Publisher. The flaw lets an attacker defeat a protection mechanism, which matters because Microsoft and CISA both treat it as exploited in the wild. The record gives no detail on the specific protection bypassed or the vulnerable code path.
Impact
An attacker can bypass a Publisher security feature, gaining high confidentiality, integrity and availability impact on the local system. The exact actions enabled are not described in the record.
Attack surface
The CVSS vector is local (AV:L) with low privileges (PR:L) and required user interaction (UI:R), so an attacker needs local access and must convince a user to open or act on a crafted Publisher file. No remote or unauthenticated path is indicated.
Exploitation
CVE-2024-38226 is listed in CISA KEV with a due date of 2024-10-01, confirming known exploitation, though EPSS 30-day probability is low at 0.02667 (84.98th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update for CVE-2024-38226 immediately; CISA's required action is to apply vendor mitigations or discontinue use of the product.
- If patching cannot be completed, restrict or block use of Microsoft Publisher and opening of untrusted Publisher files.
- Enforce least privilege so users do not operate with administrative rights, reducing the local attack surface.
- Block Publisher file attachments and downloads from external or untrusted sources at email and web gateways.
- Track KEV remediation to the 2024-10-01 due date and verify patch status across Office 2019 and LTSC installs.
Detection
- Monitor for Publisher (MSPUB.EXE) spawning unusual child processes or writing to sensitive locations.
- Alert on Publisher documents opened from email attachments, downloads or temporary directories.
- Audit endpoints for missing Microsoft Office updates matching CVE-2024-38226 and report unpatched hosts.
- Review process creation and file write telemetry around Publisher sessions for signs of protection bypass.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-38226 to the Known Exploited Vulnerabilities catalog on 10 September 2024 as "Microsoft Publisher Protection Mechanism Failure Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 1 October 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38226 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38226 | US Government Resource |
Track CVE-2024-38226 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-38226), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.