Executive brief
Microsoft Office PowerPoint is a presentation software widely used for creating business documents and slideshows. A use-after-free vulnerability in PowerPoint allows an attacker to execute malicious code on a user's system remotely, potentially giving them complete control of the affected computer and access to sensitive business presentations and data.
Technical details
A use-after-free memory safety vulnerability exists in Microsoft Office PowerPoint where freed memory is accessed after deallocation. The vulnerability is triggered remotely, likely through a specially crafted PowerPoint file that exploits the memory handling flaw. An attacker can achieve remote code execution (RCE) with high privileges on a user's system by sending a malicious presentation file; user interaction (opening the file) is typically required. The attack vector is network-based delivery of the malicious document. Microsoft has released security patches to remediate this vulnerability.
Affected products
- Microsoft Office PowerPoint <UNKNOWN>
Timeline
- 2026-09-08: disclosed