Junglewise Threat Intelligence

CVE-2026-55123: Microsoft PowerPoint heap overflow in numeric type conversion

CVE-2026-55123 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft PowerPoint 2016, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft PowerPoint is a widely used presentation software. A vulnerability in how it handles certain data could allow an attacker to take control of a user's computer if the user is tricked into opening a malicious presentation file. This could lead to the theft of sensitive information, installation of malware, or disruption of business operations.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Office PowerPoint due to incorrect conversion between numeric types (CWE-681) and improper memory management (CWE-122). The vulnerability is triggered when the application processes a specially crafted PowerPoint file. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R). Microsoft has released security updates to address this issue across various versions of Office and PowerPoint.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security release
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security release
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security release
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security release
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
  • Microsoft Microsoft PowerPoint 2016 16.0.0 to 16.0.5561.1000

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record
  • 2026-07-14: advisory: Microsoft released security update guide information

References

Related threats