Sceawere

Vulnerability Detail

CVE-2026-70316UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office PowerPoint Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:19:09.043Z",
  "pubdate": "2026-08-11T17:19:09.043Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw within Microsoft Office PowerPoint, which enables an unauthorized threat actor to execute local information disclosure attacks. The primary security impact is the unauthorized exposure of sensitive local data residing on the affected system, potentially compromising confidentiality. The affected product is Microsoft Office PowerPoint. The risk implications include the potential leakage of proprietary data, user files, or system artifacts that could be leveraged in subsequent, more targeted compromise phases. Attacker capabilities are restricted to local information disclosure without direct remote code execution or privilege escalation vectors explicitly noted in the baseline condition. Exploitation requirements mandate that the attacker possesses the ability to interact with the vulnerable application or manipulate maliciously crafted input files processed by the software. No assumptions regarding network exposure or authentication beyond local context are introduced, adhering strictly to the provided input.",
  "technicalDetails": "The root cause of the vulnerability stems from improper input validation within Microsoft Office PowerPoint when parsing specialized structures or user-supplied data inputs. The vulnerable component is the parsing engine responsible for handling document structures within PowerPoint. Because input validation routines fail to adequately sanitize or bound-check incoming parameters, anomalous or malicious input structures trigger unintended memory handling or file access patterns.\nThe exploitation method relies on supplying a specially crafted file or input sequence that forces the application to process data outside expected safety margins. The attack flow begins when the user or an unauthorized local actor introduces the malicious input into Microsoft Office PowerPoint. As the application parses the input, the lack of robust input validation causes the internal logic to mishandle the data reference, leading to the unauthorized disclosure of local information. The payload behavior centers on reading local resources or memory contents and surfacing them through application error states, rendering, or logging mechanisms accessible to the local actor.\nRegarding execution context, the vulnerability requires local access. Privilege requirements are limited to those necessary to execute or interact with Microsoft Office PowerPoint locally. Network exposure is non-applicable as the flaw manifests through local input processing vectors. Post-exploitation impact is defined by the scope of the information disclosed, which may provide reconnaissance data useful for chaining with additional local vulnerabilities or uncovering sensitive system configurations."
}
CVE-2026-70316: Microsoft Office PowerPoint Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere