Junglewise Threat Intelligence

CVE-2026-72938: Microsoft Office PowerPoint type confusion information disclosure

CVE-2026-72938 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office PowerPoint contains a type confusion vulnerability that allows an attacker to disclose sensitive information over a network. The vulnerability affects a core file-parsing component used to open and process presentation files, potentially exposing confidential data contained in presentations without requiring user authentication beyond opening a crafted file.

Technical details

A type confusion vulnerability exists in Microsoft Office PowerPoint's resource handling mechanism, where the application incorrectly processes resources of incompatible types during file parsing. This memory safety issue allows an attacker to read adjacent memory regions and disclose sensitive information. The vulnerability requires a user to open a malicious PowerPoint file, making it a network-accessible attack vector (file download or email attachment). An attacker can craft a specially formatted presentation file to trigger the type confusion and leak information such as encryption keys, user data, or other confidential content from the PowerPoint process memory. Patches are available through Microsoft's security update channels.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-09-08: disclosed

References

Related threats