Junglewise Threat Intelligence

CVE-2026-72977: Microsoft PowerPoint out-of-bounds read allows information disclosure

CVE-2026-72977 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft PowerPoint, a widely-used presentation software included in Microsoft Office, contains an out-of-bounds read vulnerability that could allow an attacker to access and disclose sensitive information over a network. This vulnerability affects the application's ability to safely process presentation files, potentially exposing confidential data contained in presentations or system memory. An attacker could exploit this by sending a specially crafted PowerPoint file to a user or leveraging network access to trigger the vulnerability.

Technical details

This vulnerability is an out-of-bounds read flaw in Microsoft PowerPoint's file processing logic. The root cause appears to be improper bounds checking when parsing presentation file structures, allowing an attacker to read memory beyond the intended buffer boundaries. The attack vector is network-based, typically requiring a user to open a malicious PowerPoint file or allowing remote exploitation in certain configurations. An attacker can achieve unauthorized information disclosure by extracting sensitive data from memory or presentation content. Patches are available from Microsoft's security update guide.

Affected products

  • Microsoft PowerPoint

Timeline

  • 2026-09-08: disclosed

References

Related threats