Impact
A use‑after‑free bug in Microsoft Office PowerPoint allows an attacker to execute code locally on the target system. The flaw occurs when a crafted presentation is processed, and it can cause the application to run arbitrary code with the privileges of the user who opens the file.
Affected Systems
The issue affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft PowerPoint 2016. All versions bundled in these product families are impacted, but no specific build numbers are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the vulnerability is not yet listed in the CISA KEV catalog. Exploitation likely requires the victim to open a malicious presentation on a susceptible system; the attacker would need to supply the crafted file, with no remote execution or network component indicated.
OpenCVE Enrichment