CVE-2025-54908
7.8Microsoft · Office PowerPoint
A use after free vulnerability in Microsoft Office PowerPoint enables a local attacker to execute arbitrary code via a specially crafted document.
Executive summary
A critical use after free vulnerability in Microsoft PowerPoint allows an unauthorized local attacker to achieve remote code execution through malicious file interaction.
Vulnerability
This is a memory corruption flaw categorized as a Use After Free (CWE-416). It can be triggered by an unauthorized local attacker when a user opens a specially crafted PowerPoint file, resulting in local code execution.
Business impact
The vulnerability poses a severe risk to organizational security, as successful exploitation results in total compromise of the affected system. With a CVSS score of 7.8, this flaw could lead to unauthorized data access, the installation of malicious software, or full system takeover, causing significant reputational and operational damage.
Remediation
Immediate Action: Apply the latest security updates provided by Microsoft via the official Update Guide immediately to remediate the vulnerability across all affected installations.
Proactive Monitoring: Monitor endpoint logs for suspicious PowerPoint process behavior, specifically looking for unexpected child processes or abnormal memory access patterns.
Compensating Controls: Advise users to exercise caution when opening unexpected files from untrusted sources and utilize security software that performs file reputation scanning.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for code execution and the total technical impact, this vulnerability must be treated as a high priority for remediation. IT administrators should prioritize the deployment of Microsoft security updates to all workstations running the affected versions of Office to eliminate the underlying memory corruption risk.
More Microsoft CVEs
Sources
- Microsoft PowerPoint Remote Code Execution Vulnerability Vendor advisory