Sceawere

Vulnerability Detail

CVE-2026-70312UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office PowerPoint Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:19:08.540Z",
  "pubdate": "2026-08-11T17:19:08.540Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw within Microsoft Office PowerPoint, which enables an unauthorized threat actor to execute local information disclosure attacks. The security defect resides in how the application processes maliciously crafted presentation inputs, failing to sufficiently sanitize or validate data before handling it. Consequently, an attacker who successfully exploits this weakness can gain unauthorized access to sensitive local system data, compromising the confidentiality boundary of the host machine.\nThe scope of affected systems includes installations of Microsoft Office PowerPoint that process untrusted presentation files. The risk implication is centered on the unauthorized exposure of local files and sensitive user data accessible in the context of the running application. Exploitation capabilities require the execution or processing of a specially crafted file, leveraging the application's parsing logic against itself. Authentication and privilege requirements are minimal for the initial execution phase, as the attack typically relies on social engineering to deliver the malicious payload to the victim. Overall, the vulnerability undermines data confidentiality through flawed input parsing mechanisms.",
  "technicalDetails": "The root cause of the vulnerability stems from improper input validation within the parsing engine of Microsoft Office PowerPoint. When the application encounters maliciously crafted file structures or embedded objects, it fails to enforce strict boundary checks and data sanitization routines. This allows anomalous input data to propagate through internal parsing functions without adequate validation, leading to memory exposure or unintended file system interaction.\nThe exploitation method relies on supplying a specially formatted PowerPoint file that triggers the parsing anomaly. The attack flow begins when an unsuspecting user opens the malicious presentation file using a vulnerable version of Microsoft Office PowerPoint. Upon processing the file, the vulnerable component executes insecure data handling operations. Because input validation is bypassed, the application inadvertently processes instructions or references embedded within the file that point to local resources or sensitive memory structures. This flaw facilitates the unauthorized retrieval or leakage of local information back to the attacker or exposes it within the application interface.\nThe vulnerable component is the file parsing and input validation subsystem responsible for interpreting PowerPoint document formats. Affected versions encompass unpatched installations of Microsoft Office PowerPoint susceptible to this specific input validation weakness. Regarding authentication and privilege requirements, the attack does not necessitate prior authentication to the underlying operating system, and the exploitation can occur under standard user privileges mapped to the victim interacting with the file. Network exposure is primarily local or dependent on vector delivery, as the payload behavior centers on local resource handling and information leakage. Post-exploitation impact is characterized by the localized compromise of sensitive data confidentiality, potentially feeding into subsequent multi-stage attack vectors."
}
CVE-2026-70312: Microsoft Office PowerPoint Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere