Sceawere
Vulnerability Detail
CVE-2026-70313UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft Office PowerPoint Information Disclosure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- Attack Type
- CWE-20: Improper Input Validation
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-11T17:19:08.663Z",
"pubdate": "2026-08-11T17:19:08.663Z",
"executiveSummary": "This vulnerability involves an improper input validation flaw within Microsoft Office PowerPoint, which enables an unauthorized threat actor to execute local information disclosure attacks.\nThe primary security impact is the unauthorized exposure of sensitive local data residing on the host machine, potentially compromising system confidentiality.\nThe affected product is Microsoft Office PowerPoint, which processes malformed input prone to validation oversights.\nThe risk implications center on the leakage of internal data structures or file contents, which could be leveraged by an attacker to facilitate subsequent, more advanced compromise vectors.\nAttacker capabilities are constrained to unauthorized local information disclosure, meaning the adversary must achieve a vector to supply improperly validated input to the application.\nExploitation requirements include the successful processing of maliciously crafted input or files by Microsoft Office PowerPoint within the local environment, resulting in the unintended exposure of information to the execution context.",
"technicalDetails": "The root cause of this vulnerability is improper input validation within the parsing and handling routines of Microsoft Office PowerPoint.\nWhen the application processes specially crafted files or input streams containing anomalous structures, the lack of rigorous boundary and type checks leads to parsing discrepancies.\nThe vulnerable component resides within the input processing subsystem of Microsoft Office PowerPoint, responsible for interpreting document structures and embedded data elements.\nExploitation occurs when an unauthorized user or process supplies maliciously engineered input that bypasses the deficient validation checks.\nThe step-by-step attack flow begins with the creation of a malicious file or data payload designed to exploit the input validation weakness.\nUpon opening or processing the file, Microsoft Office PowerPoint fails to properly sanitize or validate the incoming data streams.\nThis failure allows the underlying parser to access or reference unintended memory regions or local file paths depending on the exact implementation flaw.\nConsequently, sensitive data is inadvertently retrieved and exposed through the application interface or error-handling mechanisms.\nAuthentication requirements are minimal to none, as the application processes the input directly, though local access or a delivery vector to induce the victim application to parse the malicious input is required.\nPrivilege requirements are restricted to standard user privileges necessary to execute the application and open the crafted file.\nNetwork exposure is localized, as the vulnerability manifests primarily through local file processing rather than remote network services.\nThe post-exploitation impact is characterized by unauthorized local information disclosure, providing the attacker with internal system insights, application metadata, or user data that can aid in reconnaissance and further exploitation."
}