Description
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An Use After Free vulnerability in Microsoft Office PowerPoint enables an attacker to execute arbitrary code on the system. The flaw allows the attacker to control memory management after a freed object is accessed, permitting arbitrary code execution without authentication. This results in loss of confidentiality, integrity, and availability of the affected machine.

Affected Systems

The vulnerability impacts Microsoft 365 Apps for Enterprise, specifically the PowerPoint component. All installations of this Office suite that have not received the latest update are susceptible; version information is not provided, but the patch is distributed through the standard Office update channel.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. No EPSS score is available, and the issue is not listed in CISA KEV, implying that no publicly known exploit has been reported yet. The description states that an unauthorized attacker can exploit this flaw over a network, which suggests that network-based or attachment-based vectors are viable, and no user authentication is required to trigger the exploit.

Generated by OpenCVE AI on September 9, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft 365 Apps for Enterprise update that contains the patch for CVE-2026-80081
  • Deploy the update across all managed endpoints using WSUS, Microsoft Endpoint Manager, or an equivalent patch management solution
  • Conduct a vulnerability scan to confirm that all affected systems have the latest update applied
  • Monitor system logs and PowerPoint activity for any signs of exploitation or anomalous behavior

Generated by OpenCVE AI on September 9, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
Title Microsoft Office PowerPoint Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:34.197Z

Reserved: 2026-08-25T18:37:59.828Z

Link: CVE-2026-80081

cve-icon Vulnrichment

Updated: 2026-09-09T09:52:56.990Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:50.367

Modified: 2026-09-09T19:04:29.790

Link: CVE-2026-80081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T02:15:16Z

Weaknesses