Executive brief
A security vulnerability has been identified in Microsoft PowerPoint, the widely used presentation software. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, system instability, or a complete compromise of the affected workstation.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Office PowerPoint. The vulnerability is triggered when the application fails to properly validate input while processing a specially crafted PowerPoint file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across various versions of Office, including Microsoft 365 Apps, Office LTSC, and Office for Mac.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
- Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
- Microsoft Microsoft PowerPoint 2016 versions prior to 16.0.5561.1000
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record.
- 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability.