Impact
An out-of-bounds read in Microsoft Office PowerPoint allows an attacker with local access to read memory contents that are not intended for the process, potentially exposing sensitive data such as credentials, documents or system information. The flaw is classified as CWE‑125.
Affected Systems
Affected Microsoft Office products include Microsoft 365 Apps for Enterprise, Office 2019, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac 2021 and 2024, and Microsoft PowerPoint 2016.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate risk. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, implying no known widespread exploitation. The likely attack vector is local, requiring an attacker to have at least user-level access to a machine running a vulnerable Office version; elevated privileges would enable broader information disclosure.
OpenCVE Enrichment