Strobesstrobes
Platform
Solutions
Resources
Customers
Company
Pricing
Book a Demo
Strobesstrobes

Strobes connects every exposure signal to autonomous action, so security teams fix what matters, prove what works, and stop chasing noise.

Book a DemoTalk to an expert
ISO 27001SOC 2CREST
  • Platform
  • Platform Overview
  • Agentic Exposure Management
  • AI Agents
  • Integrations
  • API & Developers
  • Workflows & Automation
  • Analytics & Reporting
  • Solutions
  • Exposure Assessment (EAP)
  • Attack Surface Management
  • Application Security Posture
  • Risk-Based Vulnerability Management
  • Adversarial Exposure Validation (AEV)
  • AI Pentesting
  • Pentesting as a Service
  • CTEM Framework
  • By Industry
  • Financial Institutions
  • Technology
  • Retail
  • Healthcare
  • Manufacturing
  • By Roles
  • CISOs
  • Security Directors
  • Cloud Security Leaders
  • App Sec Leaders
  • Resources
  • Blog
  • Customer Stories
  • eBooks
  • Datasheets
  • Videos & Demos
  • Exposure Management Academy
  • CTEM Maturity Assessment
  • Pentest Health Check
  • Security Tool ROI Calculator
  • Company
  • About Strobes
  • Meet the Team
  • Trust & Security
  • Contact Us
  • Careers
  • Become a Partner
  • Technology Partner
  • Partner Deal Registration
  • Press Release

Weekly insight for security leaders

CTEM research, agentic AI trends, and what's actually moving the needle.

© 2026 Strobes Security Inc. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyAccessibilitySitemap
Back to Blog
Top 5 CVEs and Vulnerabilities of August 2024: Key Threats and How to Respond
CVE

Top 5 CVEs and Vulnerabilities of August 2024: Key Threats and How to Respond

Shubham JhaSeptember 3, 20247 min read

Table of Contents

  • 1. CVE-2024-38189 - Critical Remote Code Execution in Microsoft Project
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 2. CVE-2024-38178 -  Remote Code Execution Flaw in Microsoft Exchange
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 3. CVE-2024-38063 - Critical Remote Code Execution Threat in Windows TCP/IP Stack
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 4. CVE-2024-36401- Remote Code Execution Flaw in GeoServer
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 5. CVE-2024-38178 - Memory Corruption Flaw in Windows Scripting Engine
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • Conclusion: 5 CVEs & Vulnerabilities of August 2024

Authors

S
Shubham Jha

Share

Table of Contents

  • 1. CVE-2024-38189 - Critical Remote Code Execution in Microsoft Project
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 2. CVE-2024-38178 -  Remote Code Execution Flaw in Microsoft Exchange
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 3. CVE-2024-38063 - Critical Remote Code Execution Threat in Windows TCP/IP Stack
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 4. CVE-2024-36401- Remote Code Execution Flaw in GeoServer
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • 5. CVE-2024-38178 - Memory Corruption Flaw in Windows Scripting Engine
    • Details of the Vulnerability
    • Exploitation
    • Mitigation
    • Impact
    • Additional Resources
  • Conclusion: 5 CVEs & Vulnerabilities of August 2024

Authors

S
Shubham Jha

Share

Vulnerabilities of August 2024 have included some of the most eye-opening issues to surface, catching the attention of security experts across the globe. These aren't just numbers in a database they represent real challenges that need swift attention.

In this post, we'll break down the top CVEs and vulnerabilities of August 2024, giving you a clear understanding of why they stand out and what they mean for cybersecurity. Explore the threats making headlines and understand the impact they could have on your organization.

1. CVE-2024-38189 - Critical Remote Code Execution in Microsoft Project

The CVE-2024-38189 vulnerability is a critical remote code execution vulnerability that affects Microsoft Project. It allows an attacker to execute arbitrary code on a vulnerable system by tricking a user into opening a specially crafted Microsoft Project file.

Details of the Vulnerability

  • Severity: Critical
  • CVSS Score: 8.8 (CVSS v3.1)
  • Impact: Remote code execution
  • Affected Products: Microsoft Project
  • Vulnerability Type: Remote code execution
  • Exploitability: Easily exploitable
  • Authentication: Not required

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted Microsoft Project file to a target user. If the user opens the file, the attacker can execute arbitrary code on the user's system. This could allow the attacker to gain control of the system, steal data, or install malware.

Mitigation

Microsoft has released a security update to address this vulnerability. Users should install the update as soon as possible to protect their systems.

Impact

The CVE-2024-38189 vulnerability is a serious threat that could allow attackers to gain control of vulnerable systems. Users should take steps to mitigate the vulnerability as soon as possible.

Additional Resources

  • Microsoft Security Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38189
  • NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2024-38189

2. CVE-2024-38178 -  Remote Code Execution Flaw in Microsoft Exchange

The CVE-2024-38178 vulnerability is a remote code execution vulnerability that affects Microsoft Exchange Server. It allows an attacker to execute arbitrary code on a vulnerable system by sending a specially crafted email message to the server.

Details of the Vulnerability

  • Severity: High
  • CVSS Score: 7.5 (CVSS v3.1)
  • Impact: Remote code execution
  • Affected Products: Microsoft Exchange Server
  • Vulnerability Type: Remote code execution
  • Exploitability: Easily exploitable
  • Authentication: Not required

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted email message to a vulnerable Exchange Server. If the server processes the message, the attacker can execute arbitrary code on the server. This could allow the attacker to gain control of the server, steal data, or install malware.

Mitigation

Microsoft has released a security update to address this vulnerability. Users should install the update as soon as possible to protect their systems.

Impact

The CVE-2024-38178 vulnerability is a serious threat that could allow attackers to gain control of vulnerable systems. Users should take steps to mitigate the vulnerability as soon as possible.

Additional Resources

  • Microsoft Security Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178
  • NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2024-38178

3. CVE-2024-38063 - Critical Remote Code Execution Threat in Windows TCP/IP Stack

The CVE-2024-38063 vulnerability is a critical remote code execution vulnerability that affects the Windows TCP/IP stack. It allows an attacker to execute arbitrary code on a vulnerable system by sending a specially crafted packet to the system.

Details of the Vulnerability

  • Severity: Critical
  • CVSS Score: 9.8 (CVSS v3.1)
  • Impact: Remote code execution
  • Affected Products: Windows 10, Windows 11, Windows Server 2008 through 2022
  • Vulnerability Type: Remote code execution
  • Exploitability: Easily exploitable
  • Authentication: Not required

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted packet to a vulnerable system. If the system processes the packet, the attacker can execute arbitrary code on the system. This could allow the attacker to gain control of the system, steal data, or install malware.

Mitigation

Microsoft has released a security update to address this vulnerability. Users should install the update as soon as possible to protect their systems.

Impact

The CVE-2024-38063 vulnerability is a serious threat that could allow attackers to gain control of vulnerable systems. Users should take steps to mitigate the vulnerability as soon as possible.

Additional Resources

  • Microsoft Security Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063
  • NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2024-38063

4. CVE-2024-36401- Remote Code Execution Flaw in GeoServer

The CVE-2024-36401 vulnerability is a remote code execution vulnerability that affects GeoServer, an open-source web server that provides geospatial data services. It allows an attacker to execute arbitrary code on a vulnerable system by sending a specially crafted request to the server.

Details of the Vulnerability

  • Severity: Critical
  • CVSS Score: 9.8 (CVSS v3.1)
  • Impact: Remote code execution
  • Affected Products: GeoServer
  • Vulnerability Type: Remote code execution
  • Exploitability: Easily exploitable
  • Authentication: Not required

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted request to a vulnerable GeoServer instance. If the server processes the request, the attacker can execute arbitrary code on the server. This could allow the attacker to gain control of the server, steal data, or install malware.

Mitigation

GeoServer has released a security update to address this vulnerability. Users should install the update as soon as possible to protect their systems.

Impact

The CVE-2024-36401 vulnerability is a serious threat that could allow attackers to gain control of vulnerable systems. Users should take steps to mitigate the vulnerability as soon as possible.

Additional Resources

  • NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2024-36401
  • OSGeo: https://osgeo-org.atlassian.net/browse/GEOT-7587 

5. CVE-2024-38178 - Memory Corruption Flaw in Windows Scripting Engine

The CVE-2024-38178 vulnerability is a memory corruption vulnerability that affects Microsoft Windows Scripting Engine. It allows an attacker to execute arbitrary code on a vulnerable system by tricking a user into opening a specially crafted document.

Details of the Vulnerability

  • Severity: Critical
  • CVSS Score: 9.8 (CVSS v3.1)
  • Impact: Remote code execution
  • Affected Products: Microsoft Windows 10, Windows 11, Windows Server 2019, Windows Server 2022
  • Vulnerability Type: Memory corruption
  • Exploitability: Easily exploitable
  • Authentication: Not required

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted document to a target user. If the user opens the document, the attacker can execute arbitrary code on the user's system. This could allow the attacker to gain control of the system, steal data, or install malware.

Mitigation

Microsoft has released a security update to address this vulnerability. Users should install the update as soon as possible to protect their systems.

Impact

The CVE-2024-38178 vulnerability is a serious threat that could allow attackers to gain control of vulnerable systems. Users should take steps to mitigate the vulnerability as soon as possible.

Additional Resources

  • Microsoft Security Advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38178
  • NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2024-38178

Conclusion: 5 CVEs & Vulnerabilities of August 2024

As we wrap up the top CVEs of August 2024, it's clear that these vulnerabilities are more than just technical issues. They're critical challenges that demand immediate attention.

Each CVE on this list has the potential to impact systems and organizations in significant ways, underscoring the need for proactive measures and vigilant monitoring. For more detailed information on these CVEs and how to manage them effectively, check out Strobes VI platform. 

Book a demo to see how Strobes can help you stay ahead of emerging threats.

Related Reads:

  1. Top CVEs & Vulnerabilities February 2025
  2. Top CVEs & Vulnerabilities of March 2025
  3. Critical Vulnerabilities and Top CVEs of April 2025
  4. Top CVEs of May 2025: Critical Exploits, Real-World Attacks, and What You Must Patch Now
  5. Top 5 High-Risk CVEs of June 2025
Tags
Top CVE VulnerabiltiesTop Vulnerabilitiesvulnerability management

Stop chasing vulnerabilities Start reducing exposure

See how Strobes AI agents validate and fix your most critical exposures automatically.

Book a Demo
Continue Reading

Related Posts

CVE-2026-41940 - cPanel WHM Critical Pre-Auth Bypass Vulnerability
CVEVulnerability Intelligence

Top CVEs of May 2026: 5 Critical Flaws to Patch Now

Five CVEs dominated May 2026: cPanel's two-month zero-day, Linux's stealth kernel priv-esc, Langflow exploited 20 hours after disclosure, n8n's perfect-10 RCE chain, and Microsoft's SSO bypass. Here's what happened and what to do.

Jun 3, 20269 min
Top CVEs of April 2026 - CVE Roundup
CVEVulnerability Intelligence

Top 7 Critical CVEs of April 2026 You Need to Act On Now

The top CVEs of April 2026 were exploited in hours. Marimo RCE, Windows IKE, Fortinet EMS, GitHub GHES, ActiveMQ, and more. Attack scenarios, risk context, and fixes.

May 1, 202622 min
NIST Just Changed How It Tracks and Prioritizes CVEs - NVD Update 2026
CVEVulnerability Management

NIST Just Changed How It Tracks and Prioritizes CVEs

NIST has changed how it enriches CVEs in the NVD. Learn what the new risk-based triage model means for your vulnerability management program, scanner data, and remediation workflows.

Apr 29, 202613 min