CVE-2024-38152

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Aug 13, 2024
Updated: Aug 14, 2024
CWE ID 122

Summary

CVE-2024-38152 is a newly disclosed vulnerability affecting Windows systems through its Object Linking and Embedding (OLE) functionality. This remote code execution flaw allows an attacker to execute arbitrary code on vulnerable machines by manipulating specially crafted OLE packets. Successful exploitation could lead to significant security risks, including data theft, unauthorized system access, and potentially catastrophic damage. Microsoft is urging users to update their systems as soon as possible to mitigate this threat. Exploitation of this vulnerability does not require user interaction and can occur through the mere opening of a maliciously crafted file or email attachment.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows
  • Microsoft Windows 11
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft