CVE-2024-38226CISA KEV
Microsoft Publisher Protection Mechanism Failure Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files.
- Product
- Publisher
- Added to KEV
- 10 Sep 2024
- Federal remediation due
- 1 Oct 2024
- Known ransomware use
- Not reported