Junglewise Threat Intelligence

CVE-2026-69767: Microsoft Office PowerPoint use-after-free code execution

CVE-2026-69767 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office PowerPoint contains a use-after-free vulnerability that allows an attacker to execute arbitrary code on a user's computer over a network. An attacker could exploit this flaw by sending a specially crafted PowerPoint file, potentially compromising sensitive business presentations, client data, and system integrity without requiring user authorization or privileges.

Technical details

The vulnerability is a use-after-free memory safety flaw in Microsoft Office PowerPoint that can be triggered when processing a malicious PowerPoint file. The defect allows an attacker to access memory that has been freed, enabling arbitrary code execution in the context of the PowerPoint process. The attack vector is network-based and requires user interaction (opening a malicious file), but does not require prior authentication. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the user running PowerPoint. A patch from Microsoft is expected to be available through the standard security update process.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-09-08: disclosed

References

Related threats