Impact
This vulnerability arises from improper input validation in Microsoft Office PowerPoint. When a user opens a specially crafted presentation, the application exposes sensitive data that should otherwise be protected. The weakness is classified as CWE‑20, indicating unvalidated input handling.
Affected Systems
The flaw affects multiple Microsoft Office products across Windows and macOS, including Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021, Office LTSC 2024, and their Mac counterparts. According to the Microsoft security advisory, all listed versions are impacted.
Risk and Exploitability
The CVSS score of 5.5 reflects moderate severity, but the EPSS score of less than 1% indicates that exploitation is unlikely in the wild. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the attack vector is local – an attacker must have local access to the victim machine or supply a malicious file that the user opens; there is no evidence of a remote network attack possibility.
OpenCVE Enrichment