Impact
Heap‑based buffer overflow in Microsoft PowerPoint presentation file. The vulnerability exploits a buffer overrun (CWE‑122) and an integer overflow (CWE‑190), permitting the attacker to run arbitrary instructions in the context of the user who opens the file. The impact is a compromise of confidentiality, integrity, and availability of the affected machine, as malicious code can perform any actions the user is authorized to do.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office LTSC 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft PowerPoint 2016.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, while the EPSS score of <1% suggests a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector requires an adversary to supply a malicious PowerPoint file that the user opens locally; no remote network component is described in the data.
OpenCVE Enrichment