CVE-2026-69678

8.8

Microsoft · Microsoft 365 Apps for Enterprise

A use after free vulnerability in Microsoft PowerPoint allows an unauthenticated remote attacker to execute arbitrary code.

Executive summary

A critical use after free vulnerability in Microsoft Office PowerPoint products allows unauthenticated remote attackers to execute arbitrary code via specially crafted files.

Vulnerability

This is a use after free vulnerability (CWE-416) within Microsoft Office PowerPoint. The flaw allows an unauthenticated attacker to achieve remote code execution by enticing a user to open a malicious document over a network.

Business impact

The potential for remote code execution poses a severe risk to organizational security, as it can lead to total system compromise, unauthorized data exfiltration, and the installation of persistent malware. With a CVSS score of 8.8, this vulnerability is classified as high severity, indicating that the impact on confidentiality, integrity, and availability is substantial if exploited successfully.

Remediation

Immediate Action: Update all affected Microsoft Office installations to the fixed versions specified in the enrichment data provided by the vendor.

Proactive Monitoring: Monitor endpoint security logs for suspicious PowerPoint process behavior or unexpected network connections originating from the Office suite.

Compensating Controls: Utilize email filtering and security awareness training to prevent the delivery and opening of untrusted or malicious Office documents.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the potential for remote code execution, organizations must prioritize patching all instances of the affected Microsoft Office software. System administrators should verify that the specific version thresholds provided in the enrichment data are met across their fleet to ensure complete remediation of this vulnerability.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources