CVE-2025-59238

7.8

Microsoft · Office PowerPoint

A use after free vulnerability in Microsoft Office PowerPoint allows an unauthorized attacker to execute arbitrary code locally.

Executive summary

A critical use after free vulnerability in Microsoft Office PowerPoint enables unauthorized local code execution, posing a significant risk to system integrity.

Vulnerability

The flaw is a use after free vulnerability (CWE-416) triggered within the PowerPoint application. An unauthorized attacker can leverage this memory corruption issue to achieve local code execution, typically requiring user interaction such as opening a maliciously crafted file.

Business impact

Successful exploitation allows an attacker to gain control over the affected workstation, potentially leading to unauthorized data access, installation of malicious software, or further movement within the network. With a CVSS score of 7.8, this vulnerability is classified as High severity, as it enables total impact on confidentiality, integrity, and availability of the local system.

Remediation

Immediate Action: Apply the latest security updates provided via the official Microsoft Update Guide immediately to remediate the vulnerable memory handling logic.

Proactive Monitoring: Monitor for unusual PowerPoint process behavior or unexpected crash reports that may indicate exploitation attempts.

Compensating Controls: Utilize endpoint detection and response tools to monitor for suspicious child processes spawned by PowerPoint and ensure macro security policies are strictly enforced.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for complete system compromise, organizations should prioritize the deployment of the vendor-supplied patches across all affected PowerPoint installations. Ensure that users are instructed to remain vigilant regarding unsolicited documents, as local code execution vulnerabilities of this nature frequently rely on social engineering to initiate the attack sequence.

More Microsoft CVEs

Sources