Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office PowerPoint that enables an unauthenticated attacker to read sensitive data from memory when a crafted PowerPoint file is processed. This flaw flows through an improper bounds check (CWE-125) and a lack of input validation (CWE-20) and can lead to disclosure of confidential information without requiring elevated privileges.
Affected Systems
The flaw affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft PowerPoint 2016. The affected versions include all releases listed in the CNA product list, with PowerPoint 2016 explicitly noted.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity with potential confidentiality impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, which suggests that no widespread exploitation has been reported yet. The likely attack vector is remote over a network, where an attacker may deliver a malicious PowerPoint file to a target system or user to trigger the out‑of‑bounds read. No specific prerequisites beyond the ability to open the file are stated, so the risk remains moderate but present for all affected installations.
OpenCVE Enrichment