Junglewise Threat Intelligence

CVE-2026-55120: Microsoft PowerPoint heap overflow code execution

CVE-2026-55120 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft PowerPoint 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft PowerPoint, the widely used presentation software. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive data, system instability, or a complete compromise of the affected workstation.

Technical details

A heap-based buffer overflow (CWE-122) exists in Microsoft Office PowerPoint. The vulnerability is triggered when the application fails to properly validate input while processing a specially crafted PowerPoint file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Microsoft has released security updates to address this issue across various versions of Office, including Microsoft 365 Apps, Office LTSC, and Office for Mac.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC for Mac 2021 versions prior to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 versions prior to 16.111.26071215
  • Microsoft Microsoft PowerPoint 2016 versions prior to 16.0.5561.1000

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record.
  • 2026-07-14: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats