Impact
The flaw is a use‑after‑free vulnerability in Microsoft Office PowerPoint that permits an attacker to execute arbitrary code over the network without authorization. Classified as CWE‑416, the error arises from improper memory deallocation during slide processing, which can lead to arbitrary code execution within the application and potentially the host operating system. An adversary who exploits this flaw could run malicious payloads, exfiltrate information, or establish persistence for later attacks.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft PowerPoint 2016 are all affected. All current installations of these products are considered vulnerable until a Microsoft patch has been deployed.
Risk and Exploitability
A CVSS score of 8.8 indicates high severity. The EPSS score is unavailable, so the current exploit probability is unknown, but the vulnerability can be triggered remotely over the network using a crafted PowerPoint file or document. Because the flaw is not listed in the CISA KEV catalog, there is no confirmed exploitation in the wild yet, yet the remote nature of the attack and the high severity leave the system exposed to full compromise if exploited.
OpenCVE Enrichment