Impact
Microsoft Office PowerPoint contains an out‑of‑bounds read that allows an attacker to read memory beyond the intended buffer when processing a PowerPoint file. The exposed memory may contain sensitive data, and the vulnerability can be triggered by a maliciously crafted presentation opened by a user or accepted over a network. The impact is the unauthorized disclosure of confidential information.
Affected Systems
Affected are Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Office 2021 LTSC, Office 2024 LTSC, Office 365 for Mac, Office LTSC for Mac 2021 and 2024, and PowerPoint 2016. All listed versions are impacted, with no specific revision numbers provided.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity with an availability of sufficient impact if exploited. No EPSS score is available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, but the potential for data leakage makes it a concern. Attackers must supply a malicious PowerPoint file that triggers the out‑of‑bounds read, which typically requires the victim to open the file or a similar user interaction, making the threat primarily local to users who accept unknown presentation files.
OpenCVE Enrichment