Junglewise Threat Intelligence

CVE-2026-68809: Microsoft Office PowerPoint incomplete cleanup information disclosure

CVE-2026-68809 · Severity: medium · CVSS 5.5 · Published 2026-08-11

Technologies: Microsoft Office PowerPoint. Vendors: Microsoft.

Executive brief

Microsoft Office PowerPoint contains a memory cleanup vulnerability that allows a local attacker to access sensitive information that should have been cleared from memory. An unauthorized user with access to an affected system could potentially read confidential data left behind in memory after PowerPoint operations, posing a risk to document confidentiality and organizational information security.

Technical details

The vulnerability is classified as incomplete cleanup of sensitive data in memory within Microsoft Office PowerPoint. The root cause involves the application failing to properly clear or overwrite sensitive information from memory after processing. The attack vector is local, requiring an attacker to have direct access to the affected system or ability to execute code with appropriate privileges. The vulnerability allows an attacker to read information from memory that should have been securely cleared, potentially exposing document contents or other sensitive data. A patch has been released by Microsoft as indicated by the security update guide reference.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-08-11: disclosed

References

Related threats