Junglewise Threat Intelligence

CVE-2026-72956: Microsoft Office PowerPoint untrusted pointer dereference

CVE-2026-72956 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office PowerPoint, a widely-used presentation software, contains a vulnerability that allows an attacker to craft a malicious presentation file. When opened by a user, the flaw could enable an attacker to read sensitive information from the user's system without requiring authentication, potentially exposing confidential business data or personal information.

Technical details

This vulnerability is a classic untrusted pointer dereference issue in Microsoft Office PowerPoint's presentation parsing code. An attacker can craft a specially-formed PowerPoint file (.pptx or similar) containing malicious pointer values that, when processed by the application, cause arbitrary memory to be read. The attack requires user interaction (opening the file) over a network vector. Successful exploitation results in information disclosure from the vulnerable process's memory address space. A patch is available through Microsoft Security Updates.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-09-08: disclosed

References

Related threats