Executive brief
A security vulnerability has been identified in Microsoft PowerPoint, the widely used presentation software. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, unauthorized changes to files, or a complete compromise of the affected system.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office PowerPoint due to improper handling of objects in memory, potentially triggered by an underlying integer overflow. The vulnerability is locally exploitable but requires user interaction, typically involving a victim opening a maliciously crafted PowerPoint file. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. Affected versions include various releases of Office 2016, 2019, LTSC 2021/2024, and Microsoft 365 Apps on both Windows and macOS. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 and later versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 and later versions prior to 16.111.26071215
- Microsoft Microsoft PowerPoint 2016 versions prior to 16.0.5561.1000
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory