CVE-2026-69767
8.8Microsoft · Microsoft Office PowerPoint
A use after free vulnerability in Microsoft Office PowerPoint allows an unauthenticated attacker to execute arbitrary code over a network.
Executive summary
A critical use after free vulnerability in Microsoft Office PowerPoint enables remote code execution, posing a significant risk to organizational endpoints.
Vulnerability
This vulnerability is a use after free (CWE-416) flaw within PowerPoint that can be triggered by an unauthenticated attacker. Successful exploitation allows the attacker to achieve remote code execution on the target system, typically requiring user interaction.
Business impact
The ability to execute remote code on a workstation poses a severe threat to business operations, as it can lead to full system compromise, unauthorized data exfiltration, and lateral movement within the network. With a CVSS score of 8.8, this vulnerability is classified as high severity, indicating a high potential for significant impact on confidentiality, integrity, and availability of corporate assets.
Remediation
Immediate Action: Update all affected Microsoft Office installations to the specified fixed versions immediately to remediate the underlying memory management flaw.
Proactive Monitoring: Review endpoint security logs for unusual process spawning originating from PowerPoint, such as the execution of shell commands or suspicious network connections.
Compensating Controls: Ensure that attack surface reduction rules are enabled on managed endpoints to block Office applications from creating child processes.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the nature of use after free vulnerabilities, organizations should prioritize the deployment of the vendor-supplied security updates. Administrators must ensure that all instances of Microsoft Office are updated to the versions listed above to eliminate this attack vector and prevent potential compromise.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- Microsoft Office PowerPoint Remote Code Execution Vulnerability Vendor advisory