Impact
An Use After Free vulnerability in Microsoft Office PowerPoint enables an attacker to execute arbitrary code on the system. The flaw allows the attacker to control memory management after a freed object is accessed, permitting arbitrary code execution without authentication. This results in loss of confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability impacts Microsoft 365 Apps for Enterprise, specifically the PowerPoint component. All installations of this Office suite that have not received the latest update are susceptible; version information is not provided, but the patch is distributed through the standard Office update channel.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. No EPSS score is available, and the issue is not listed in CISA KEV, implying that no publicly known exploit has been reported yet. The description states that an unauthorized attacker can exploit this flaw over a network, which suggests that network-based or attachment-based vectors are viable, and no user authentication is required to trigger the exploit.
OpenCVE Enrichment