CVE-2026-69797

8.8

Microsoft · Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, Office LTSC 2024

A use after free vulnerability in Microsoft PowerPoint allows an unauthenticated attacker to achieve remote code execution via a network vector.

Executive summary

A critical use after free vulnerability in Microsoft PowerPoint components across multiple Office versions poses a significant risk of remote code execution.

Vulnerability

The flaw is a use after free (CWE-416) condition within Microsoft PowerPoint, which can be triggered by an unauthenticated attacker over a network. Successful exploitation requires user interaction to open a malicious file or interact with a compromised resource.

Business impact

This vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to complete system compromise. If exploited, an attacker could gain the same privileges as the logged in user, potentially leading to unauthorized data access, lateral movement within the network, or the installation of persistent malware. Given the ubiquity of Microsoft Office in corporate environments, this flaw presents a substantial threat to organizational security and operational integrity.

Remediation

Immediate Action: Apply the vendor security updates provided by Microsoft for the specific Office product versions listed in the enrichment data.

Proactive Monitoring: Monitor network traffic for unusual PowerPoint file transfers and review endpoint detection logs for unexpected process execution originating from Office applications.

Compensating Controls: Ensure that Protected View and Application Guard are enabled for all Office users to restrict the execution of untrusted documents.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of the latest Microsoft security patches to all affected workstations and servers. Given the potential for remote code execution, this update should be integrated into the standard patch management cycle with high urgency to minimize the window of exposure.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources