Impact
The vulnerability arises from an incomplete cleanup routine in Microsoft Office PowerPoint, allowing an unauthorized local attacker to recover residual data after a presentation is closed. The flaw can expose confidential content that was stored temporarily by PowerPoint, thereby leaking sensitive information. The primary impact is the disclosure of protected data through local means.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft PowerPoint 2016. The available information does not specify which releases are affected, so version details are unavailable and the vulnerability may impact any of the listed products.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local attacker with access to a target machine and the ability to open or manipulate a PowerPoint file, after which the incomplete cleanup may expose residual data. The attack vector is therefore local, and no remote exploitation capability is described.
OpenCVE Enrichment