logo

Microsoft Office Spoofing Vulnerability Let Attackers Steal Sensitive Data

ID: cf17987e-17fc-51b7-9970-3a6cefec3dfc

STIX ID: report--cf17987e-17fc-51b7-9970-3a6cefec3dfc

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2024-08-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft disclosed CVE-2024-38200, a spoofing vulnerability (CVSS 7.5) affecting Office 2016, Office 2019, Office LTSC 2021 and Microsoft 365 Apps (32/64-bit) that could allow exposure of sensitive information via specially crafted files delivered through malicious or compromised websites; Microsoft assesses active exploitation as "less likely". The company deployed an interim fix via Feature Flighting on July 30, 2024 and plans a formal patch on August 13, 2024; recommended mitigations include restricting NTLM traffic, placing high-value accounts in the Protected Users group, and blocking outbound TCP 445.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.