Impact
Microsoft Office PowerPoint is affected by a type‑confusion bug that permits an attacker to read data that the application treats as incompatible, leading to disclosure of sensitive information. The flaw can be exercised over a network, enabling remote information leakage. The vulnerability is associated with CWE‑822 and CWE‑843, indicating type‑confusion and type‑casting issues.
Affected Systems
The affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 2021, Microsoft Office 2024, Office LTSC 2021, Office LTSC 2024, Office 365 for Mac, and Office LTSC for Mac 2021 and 2024. All versions listed by Microsoft are vulnerable until the patch is applied.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is judged moderate. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation to date. Based on the description, it is inferred that an attacker could trigger the bug by delivering crafted PowerPoint content over a network connection, potentially exposing memory or configuration data. While no public exploit is known, the risk remains theoretical but warrants prompt mitigation.
OpenCVE Enrichment