Impact
A use‑after‑free flaw in Microsoft Office PowerPoint allows an attacker to execute arbitrary code when a specially crafted file is opened. This memory safety error, classified as CWE‑416, gives the attacker the same privileges as the user running PowerPoint, potentially enabling full control over the host system.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft PowerPoint 2016. Microsoft’s advisory lists all vulnerable versions for these releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, so the exact likelihood of exploitation remains uncertain. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed incidents to date. Based on the description, it is inferred that the likely attack vector involves a malicious PowerPoint file transmitted over a network, which the victim must open for exploitation to succeed. This inference follows from the nature of a use‑after‑free that requires code execution through deserialization of user‑controlled data. Consequently, the risk is significant for environments that share files externally, as the attacker only needs network access and the user’s interaction to trigger the flaw.
OpenCVE Enrichment