Executive brief
Microsoft Office PowerPoint contains a memory access vulnerability that allows an attacker to read sensitive information from affected systems over a network without authentication. An attacker could exploit this flaw to disclose confidential data contained in memory, potentially exposing business-critical information or credentials. No authentication is required and the attack can be conducted remotely.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Office PowerPoint that allows information disclosure. The flaw exists in the presentation processing logic, enabling an attacker to craft a malicious file or send specially crafted network traffic that triggers the out-of-bounds memory access. When a user opens the malicious file or the system processes the crafted input, the application reads memory beyond intended boundaries, potentially exposing sensitive data. The attack vector is network-based and does not require user authentication, though it may require user interaction to open a malicious document. No publicly known active exploitation has been reported as of the advisory date.
Affected products
- Microsoft Office PowerPoint
Timeline
- 2026-09-08: disclosed