Description
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in Microsoft Office PowerPoint that allows an attacker to read memory contents and transmit the data over a network, resulting in an information disclosure. This flaw is a classic buffer over‑read (CWE‑125) and does not provide direct code execution or denial of service. The attacker can disclose sensitive information such as passwords, documents, or other confidential data that resides in memory.

Affected Systems

This issue affects a wide range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 365 for Mac, and the long‑term servicing channel editions for both Windows and macOS (LTSC 2021 and LTSC 2024). All supported versions of these products on Windows and macOS are susceptible, as indicated by the CNA and the associated CPE list.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, and because EPSS data is not available, the current exploitation probability is unclear. The flaw is not listed in the CISA KEV catalog, suggesting that no large‑scale public exploits have been documented. The likely attack vector is local or remote via PowerPoint files or network traffic that the application initiates, but the specific exploitation scenario is inferred from the description of memory leakage over a network. Until an official patch is applied, the vulnerability could be abused by privileged or local users to harvest memory and exfiltrate data to a remote adversary.

Generated by OpenCVE AI on September 9, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update addressing CVE-2026-80086 from the official update guide.
  • Update all affected Office applications to the latest security‑patched version.
  • Configure firewall or application‑layer filters to block outbound connections from PowerPoint to untrusted endpoints.
  • Disable external content download and execution within PowerPoint to reduce vulnerable code paths.
  • Monitor outbound network traffic from Office for anomalous data exfiltration and investigate suspicious activity.

Generated by OpenCVE AI on September 9, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
Vendors & Products Microsoft microsoft 365

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
Title Microsoft Office PowerPoint Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:29.798Z

Reserved: 2026-08-25T18:37:59.829Z

Link: CVE-2026-80086

cve-icon Vulnrichment

Updated: 2026-09-08T20:00:48.691Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:51.003

Modified: 2026-09-17T20:18:35.403

Link: CVE-2026-80086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:15:17Z

Weaknesses