Executive brief
Microsoft PowerPoint is a widely used presentation software. A vulnerability in how it handles certain data could allow an attacker to take control of a user's computer if the user is tricked into opening a malicious presentation file. This could lead to the theft of sensitive information, installation of malware, or disruption of business operations.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Office PowerPoint due to incorrect conversion between numeric types (CWE-681) and improper memory management (CWE-122). The vulnerability is triggered when the application processes a specially crafted PowerPoint file. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R). Microsoft has released security updates to address this issue across various versions of Office and PowerPoint.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security release
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security release
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security release
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security release
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
- Microsoft Microsoft PowerPoint 2016 16.0.0 to 16.0.5561.1000
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record
- 2026-07-14: advisory: Microsoft released security update guide information