Executive brief
Microsoft Office PowerPoint is a widely-used presentation application included in Office suites across enterprises and individual users. A use-after-free vulnerability allows an attacker to execute arbitrary code remotely by sending a specially crafted file, potentially compromising user systems and gaining unauthorized access to corporate data and networks.
Technical details
A use-after-free vulnerability in Microsoft Office PowerPoint permits remote code execution when processing malicious presentation files. The vulnerability exists in PowerPoint's memory management, where a freed object is accessed in an unsafe manner, allowing an attacker to overwrite memory and achieve arbitrary code execution. Attack vectors include network-based delivery of malicious Office files, with no authentication required but typically requiring user interaction to open the file. An attacker can exploit this to gain code execution in the context of the user running PowerPoint. Patches are available from Microsoft.
Affected products
- Microsoft Office PowerPoint <UNKNOWN>
Timeline
- 2026-09-08: disclosed