Impact
The vulnerability arises from improper input validation in Microsoft Office PowerPoint, enabling an unauthorized local attacker to read sensitive data that should otherwise remain confidential. The weakness allows disclosure of information from the host system, potentially revealing user data or configuration details stored on the device. The exploit does not provide remote code execution but can compromise privacy and contextual integrity of the user’s environment.
Affected Systems
Affected Microsoft products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, and the long‑term servicing channel releases of Office 2021 and 2024, both on Windows and Mac. The CVE listing does not specify granular version fall‑throughs, so any installation of these editions that has not been updated may be vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of less than 1% points to a low probability of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, suggesting no known widespread attacks. Based on the description, the likely attack vector is local, implying that the attacker must have ongoing access to the target machine, possibly through a shared drive or removable media that carries a malicious PowerPoint file.
OpenCVE Enrichment