CVE-2024-38189

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
43.66%
probability
This CVE has a 43.66% probability of being exploited in the next 30 days.
0% Top 97.6th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Microsoft Project Remote Code Execution Vulnerability

Attack Intelligence

Google Project Zero

Patched
Aug. 13, 2024
Reported by
???
Root Cause Analysis
???

Signal Intelligence

Confidence
82%
EPSS 43.66%
Mentions 3
Last Seen Aug 13, 2024

CNA Information

Analyst Note

This CVE is confirmed as a zero-day RCE vulnerability in Microsoft Project with a high CVSS score (8.8) and documented exploitation. While not yet listed in CISA KEV, its inclusion in Google Project Zero and Microsoft's August 2024 Patch Tuesday as one of 9 zero-days with 6 actively exploited variants provides strong evidence of legitimacy.

Triage Info

Decided atMar 03, 2026