Impact
The vulnerability is an improper access control flaw in Microsoft PowerPoint for Android that permits an attacker who already has authorized access to the device to spoof locally, potentially impersonating other users or content. This could allow the attacker to alter presentation data or trick users into trusting manipulated files, compromising data integrity and possibly leading to social engineering attacks. The flaw is classified as CWE-284.
Affected Systems
Microsoft PowerPoint for Android is affected. The vulnerability applies to all versions of the application available through the Google Play Store, as the CNA does not list specific version numbers.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the medium severity range. No EPSS score is available, and it is not listed in KEV, indicating that there is no known public exploitation yet. Because the flaw requires an attacker to already have authorized access to the device, the attack vector is local; however, if a malicious actor gains physical or authorised remote access, the vulnerability could be used to spoof within the app. The overall risk is moderate, and timely mitigation is recommended.
OpenCVE Enrichment