CVE detail
CVE-2024-38226
Microsoft Publisher Security Feature Bypass Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 18.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- Week in review: Veeam Backup & Replication RCE could soon be exploited, Microsoft fixes 4 0-daysHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam Backup & Replication RCE flaw may soon be leveraged by ransomware gangs (CVE-2024-40711) CVE-2024-40711, a critical vulnerability affecting Veeam Backup & Replication (VBR), could soon be exploited by attackers to steal enterprise data. Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixes September 2024 Patch Tuesday is here and Microsoft has delivered 79 fixes, … More →
newswww.helpnetsecurity.comSep 15, 2024, 8:00 AM - Microsoft Patch Tuesday security updates for September 2024 addressed four actively exploited zero-daysSecurity Affairs
Microsoft Patch Tuesday security updates for September 2024 addressed 79 flaws, including four actively exploited zero-day flaws. Microsoft Patch Tuesday security updates for September 2024 addressed 79 vulnerabilities in Windows and Windows Components; Office and Office Components; Azure; Dynamics Business Central; SQL Server; Windows Hyper-V; Mark of the Web (MOTW); and the Remote Desktop Licensing […]
newssecurityaffairs.comSep 11, 2024, 7:07 AM - Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixesHelp Net Security
September 2024 Patch Tuesday is here and Microsoft has delivered 79 fixes, including those for a handful of zero-days (CVE-2024-38217, CVE-2024-38226, CVE-2024-38014, CVE-2024-43461) exploited by attackers in the wild, and a Windows 10 code defect (CVE-2024-43491) that rolled back earlier CVE fixes. The actively exploited flaws Let’s start with the only one that was previously publicly known: CVE-2024-38217, a vulnerability that allows attackers to bypass Mark of the Web (MotW). Elastic Security researcher Joe Desimone … More →
newswww.helpnetsecurity.comSep 10, 2024, 7:41 PM Patch Tuesday: Microsoft raises an alarm for in-the-wild exploitation of a critical flaw in Windows Update.
newswww.securityweek.comSep 10, 2024, 7:06 PMNo excerpt available.
Mitigationwww.cisa.govSep 10, 2024, 5:15 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38226msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comSep 10, 2024, 5:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-20673CVSS 7.8 · High
Microsoft Office Remote Code Execution Vulnerability
- CVE-2025-21346CVSS 7.1 · High
Microsoft Office Security Feature Bypass Vulnerability
- CVE-2023-33150CVSS 9.6 · Critical
Microsoft Office Security Feature Bypass Vulnerability
- CVE-2022-33631CVSS 7.3 · High
Microsoft Excel Security Feature Bypass Vulnerability
- CVE-2024-38189CVSS 8.8 · High
Microsoft Project Remote Code Execution Vulnerability
- CVE-2024-21413CVSS 9.8 · Critical
Microsoft Outlook Remote Code Execution Vulnerability