Executive brief
Microsoft Office PowerPoint, a widely-used presentation software, contains a vulnerability that allows an attacker to craft a malicious presentation file. When opened by a user, the flaw could enable an attacker to read sensitive information from the user's system without requiring authentication, potentially exposing confidential business data or personal information.
Technical details
This vulnerability is a classic untrusted pointer dereference issue in Microsoft Office PowerPoint's presentation parsing code. An attacker can craft a specially-formed PowerPoint file (.pptx or similar) containing malicious pointer values that, when processed by the application, cause arbitrary memory to be read. The attack requires user interaction (opening the file) over a network vector. Successful exploitation results in information disclosure from the vulnerable process's memory address space. A patch is available through Microsoft Security Updates.
Affected products
- Microsoft Office PowerPoint
Timeline
- 2026-09-08: disclosed