Junglewise Threat Intelligence

CVE-2026-72975: Microsoft Office PowerPoint out-of-bounds read

CVE-2026-72975 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Office PowerPoint contains a memory access vulnerability that allows an attacker to read sensitive information from affected systems over a network without authentication. An attacker could exploit this flaw to disclose confidential data contained in memory, potentially exposing business-critical information or credentials. No authentication is required and the attack can be conducted remotely.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Office PowerPoint that allows information disclosure. The flaw exists in the presentation processing logic, enabling an attacker to craft a malicious file or send specially crafted network traffic that triggers the out-of-bounds memory access. When a user opens the malicious file or the system processes the crafted input, the application reads memory beyond intended boundaries, potentially exposing sensitive data. The attack vector is network-based and does not require user authentication, though it may require user interaction to open a malicious document. No publicly known active exploitation has been reported as of the advisory date.

Affected products

  • Microsoft Office PowerPoint

Timeline

  • 2026-09-08: disclosed

References

Related threats