Junglewise Threat Intelligence

CVE-2026-41102: Microsoft Office PowerPoint improper access control spoofing

CVE-2026-41102 · Severity: high · CVSS 7.1 · Published 2026-05-12

Executive brief

A security vulnerability exists in Microsoft PowerPoint that could allow an authorized user on a system to misrepresent information or impersonate legitimate content. This flaw stems from improper access controls within the application. If exploited, it could lead to the unauthorized modification of data or the presentation of deceptive information to other users on the same machine.

Technical details

A local spoofing vulnerability exists in Microsoft Office PowerPoint due to improper access control (CWE-284). An attacker with low-privileged local access to a system can exploit this flaw to bypass security restrictions and misrepresent content or identity within the application. The attack vector is local, meaning the attacker must already have the ability to execute code or access the target system. Successful exploitation could result in high impacts to data confidentiality and integrity, though it does not directly impact system availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security advisory.

References

Related threats