Impact
The vulnerability arises from improper input validation in Microsoft Office PowerPoint, which permits a local attacker who can supply specially crafted content to read protected information from the victim’s machine. Because the flaw is confined to local execution, the primary effect is local information disclosure rather than remote code execution, aligning with CWE‑20 (Improper Input Validation). The lack of a required privilege escalation barrier means any user with access to a PowerPoint file can exploit the issue to retrieve sensitive data.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, and Microsoft Office LTSC for Mac 2024. Version associations are not specified beyond these product families, meaning all released iterations of these suites are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely in the wild at present. Because the vulnerability requires a local attacker to deliver crafted PowerPoint content, the attack vector is inferred to be local file manipulation rather than remote network exploitation. The vulnerability is not listed in CISA’s KEV catalog, further implying a lower current threat level.
OpenCVE Enrichment