Impact
A heap‑based buffer overflow in Microsoft Office PowerPoint allows an attacker who supplies a crafted document to trigger the overflow and run arbitrary code in the context of the user who opens the file. The vulnerability does not provide remote or elevated system‑level access beyond the local user’s privileges.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft PowerPoint 2016 are affected. No specific minor version numbers are listed in the CNA data, so all current releases of these products remain vulnerable until updated.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of <1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires an attacker to deliver a crafted file that a user opens locally, without the need for remote network access.
OpenCVE Enrichment