CVE-2024-38200General(microsoft / 365_apps)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Office Spoofing Vulnerability

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channel

4 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-05: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-23: 1Active Exploitation · 2026-04-23: 102-0504-23
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-02-051
General1
2026-04-231
Active Exploitation1
Full discourse2 posts
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CVE-2024-38200 & CVE-2024-38201: Active Exploitation of Windows Defender — Dete… "Critical Windows Defender flaws are under active attack. Detect weaponization of native…" 🔗 https://securityarsenal.com/blog/cve-2024-38200-and-cve-2024-38201-active-exploitation-of-windows-defender-detection-and-hardening-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The tweet announces that CVE-2024-38200 and CVE-2024-38201 are actively exploited in Windows Defender, with weaponized native tools and a call for urgent mitigation.

    0000074
    11 followersView on X
  • ACCESSYSTEM® Technology Inc.@ACCESSYSTEM_IT
    General

    Stop just patching. Start hardening. The recent Microsoft Office zero-day (CVE-2024-38200) proves an uncomfortable truth if your security strategy relies entirely on "Patch" you are already behind sales@accessystem.com #CyberSecurity #CISO #RiskManagement #Microsoft #ACCESSYSTEM https://t.co/DZTCmGMmq8

    Post summary

    The tweet references the Microsoft Office zero-day CVE-2024-38200 and warns that relying solely on patching is insufficient, urging stronger hardening measures.

    0000077
    351 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps--x64
Appmicrosoft365_apps--x86
Appmicrosoftoffice2016-x64
Appmicrosoftoffice2016-x86
Appmicrosoftoffice2019-x64
Appmicrosoftoffice2019-x86
Appmicrosoftoffice_long_term_servicing_channel2021-x64
Appmicrosoftoffice_long_term_servicing_channel2021-x86

Explore more