Executive brief
Microsoft Office PowerPoint contains a memory cleanup vulnerability that allows a local attacker to access sensitive information that should have been cleared from memory. An unauthorized user with access to an affected system could potentially read confidential data left behind in memory after PowerPoint operations, posing a risk to document confidentiality and organizational information security.
Technical details
The vulnerability is classified as incomplete cleanup of sensitive data in memory within Microsoft Office PowerPoint. The root cause involves the application failing to properly clear or overwrite sensitive information from memory after processing. The attack vector is local, requiring an attacker to have direct access to the affected system or ability to execute code with appropriate privileges. The vulnerability allows an attacker to read information from memory that should have been securely cleared, potentially exposing document contents or other sensitive data. A patch has been released by Microsoft as indicated by the security update guide reference.
Affected products
- Microsoft Office PowerPoint
Timeline
- 2026-08-11: disclosed