Junglewise Threat Intelligence

CVE-2026-78513: Microsoft PowerPoint out-of-bounds read information disclosure

CVE-2026-78513 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft PowerPoint contains a memory reading vulnerability that could allow an attacker to access sensitive information from a user's system. An attacker would need to trick a user into opening a specially crafted PowerPoint file to exploit this flaw, potentially exposing confidential data or other sensitive details stored in memory.

Technical details

The vulnerability is an out-of-bounds read flaw in Microsoft Office PowerPoint that allows information disclosure. The vulnerability is triggered when processing malformed or specially crafted PowerPoint files, resulting in the application reading memory beyond its intended boundaries. This requires user interaction (opening a malicious file) and operates with local/file-based attack vectors. A successful exploit could leak sensitive information from the affected process memory. The vulnerability has a CVSS score of 5.5 (medium severity).

Affected products

  • Microsoft PowerPoint

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats