CVE-2024-38189
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
3 articles
EPSS Score
Source: FIRST.org · 2026-05-24
43.66%
probability
This CVE has a 43.66% probability
of being exploited in the next 30 days.
0%
Top 97.6th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroMicrosoft Project Remote Code Execution Vulnerability
Google Project Zero
Patched
Aug. 13, 2024
Reported by
???
Root Cause Analysis
???
Microsoft and Adobe Patch Tuesday, August 2024 Security Update Review
Qualys
Aug 13, 2024
Microsoft August 2024 Patch Tuesday fixes 9 zero-days, 6 exploited
BleepingComputer
Aug 13, 2024
Signal Intelligence
Confidence
82%
EPSS
43.66%
Mentions
3
Last Seen
Aug 13, 2024
CNA Information
Analyst Note
This CVE is confirmed as a zero-day RCE vulnerability in Microsoft Project with a high CVSS score (8.8) and documented exploitation. While not yet listed in CISA KEV, its inclusion in Google Project Zero and Microsoft's August 2024 Patch Tuesday as one of 9 zero-days with 6 actively exploited variants provides strong evidence of legitimacy.
Triage Info
Decided atMar 03, 2026