CVE-2025-53761

7.8

Microsoft · Office PowerPoint

A use after free vulnerability in Microsoft Office PowerPoint allows an unauthorized local attacker to execute arbitrary code.

Executive summary

A critical use after free vulnerability in Microsoft PowerPoint permits local code execution, posing a significant risk to endpoint integrity.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Microsoft Office PowerPoint application. An attacker can exploit this flaw to achieve local code execution, provided they can induce a user to open a specially crafted malicious file.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain code execution on the local machine with the privileges of the logged-in user. This could lead to full system compromise, the installation of malware, or the exfiltration of sensitive organizational data. Given the CVSS score of 7.8, this vulnerability is categorized as High severity, necessitating prompt attention to prevent potential lateral movement within the network.

Remediation

Immediate Action: Apply the latest Microsoft security updates immediately by visiting the official Microsoft Security Update Guide.

Proactive Monitoring: Monitor endpoint security logs for unexpected process spawns from the PowerPoint application, such as cmd.exe or PowerShell.exe.

Compensating Controls: Utilize endpoint detection and response (EDR) solutions to block suspicious file execution patterns and enforce restricted user privileges to limit the impact of code execution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of the provided security patches across all affected workstations and servers. Given the potential for total system compromise, administrators must ensure that all instances of Microsoft Office are updated to the versions specified in the Microsoft security release. Failure to patch may expose the environment to future exploitation of this flaw.

More Microsoft CVEs

Sources