Impact
The vulnerability is an out‑of‑bounds read in Microsoft Office PowerPoint that allows an attacker to read memory contents and transmit the data over a network, resulting in an information disclosure. This flaw is a classic buffer over‑read (CWE‑125) and does not provide direct code execution or denial of service. The attacker can disclose sensitive information such as passwords, documents, or other confidential data that resides in memory.
Affected Systems
This issue affects a wide range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 365 for Mac, and the long‑term servicing channel editions for both Windows and macOS (LTSC 2021 and LTSC 2024). All supported versions of these products on Windows and macOS are susceptible, as indicated by the CNA and the associated CPE list.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and because EPSS data is not available, the current exploitation probability is unclear. The flaw is not listed in the CISA KEV catalog, suggesting that no large‑scale public exploits have been documented. The likely attack vector is local or remote via PowerPoint files or network traffic that the application initiates, but the specific exploitation scenario is inferred from the description of memory leakage over a network. Until an official patch is applied, the vulnerability could be abused by privileged or local users to harvest memory and exfiltrate data to a remote adversary.
OpenCVE Enrichment