CVE-2024-38173: 365 Apps Vulnerability (CVSS 6.7) — Fix & Details

CVE-2024-38173 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Microsoft Outlook Remote Code Execution Vulnerability. EPSS estimates a 0.66% chance of exploitation in the next 30 days.

Description

Microsoft Outlook Remote Code Execution Vulnerability

Metrics

Weakness Enumeration

Affected Software

Vendor Product Versions
Microsoft 365 Apps All versions
Microsoft Office 2019
Microsoft Office Long Term Servicing Channel 2021
Microsoft Outlook 2016

References

Timeline

Frequently Asked Questions

What is CVE-2024-38173?

Microsoft Outlook Remote Code Execution Vulnerability

How severe is CVE-2024-38173?

CVE-2024-38173 has a CVSS score of 6.7/10 (MEDIUM severity). The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.

How do I fix CVE-2024-38173?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.