Impact
A pointer dereference flaw in Microsoft Office PowerPoint allows an attacker who can supply untrusted data to an Office application to read memory contents and transmit the data over a network connection. The flaw does not permit code execution or denial of service, but it can expose sensitive configuration or user data that the application can access.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft Office LTSC 2024. The vulnerability applies to all supported installations of these products; specific patch releases have not been enumerated in the supplied data.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate impact. An attacker can exploit the vulnerability from a remote network location, as the flaw can be triggered by network delivered content. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation evidence. Nonetheless, the attack vector is likely remote, and affected systems that process PowerPoint files from network sources remain at risk.
OpenCVE Enrichment