Sceawere

Vulnerability Detail

CVE-2026-70320UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office PowerPoint Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:19:09.633Z",
  "pubdate": "2026-08-11T17:19:09.633Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw residing within Microsoft Office PowerPoint. The security defect allows an unauthorized, locally positioned attacker to execute unauthorized information disclosure attacks against targeted systems. The primary impact of successful exploitation includes the unauthorized extraction of sensitive local data accessible to the user context running the vulnerable application. Risk implications involve potential exposure of confidential files and internal system architecture details to malicious actors who have achieved local execution capabilities. Attacker capabilities are restricted to local access vectors, meaning the adversary must already possess a foothold on the host machine or trick a user into opening a specially crafted file capable of triggering the input validation failure. Exploitation requirements mandate that the victim opens a malicious PowerPoint document processed by the flawed parsing engine, thereby triggering the anomalous behavior. No explicit remote network exposure is inherently required for the core vulnerability mechanism, as the flaw is bound to local file parsing and input sanitization routines within Microsoft Office PowerPoint.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient input validation checks within the Microsoft Office PowerPoint file parsing architecture. When the application ingests and processes specially formatted presentation structures, it fails to properly sanitize or validate specific input fields, leading to memory inspection or unauthorized file reference resolution. The vulnerable component resides within the parsing and rendering subsystems of Microsoft Office PowerPoint responsible for handling complex object containers and embedded data references. Authentication requirements are non-existent for the local execution vector, and privilege requirements are limited to standard user privileges necessary to launch the application and open the crafted document. Network exposure is localized, requiring the file to be present locally or accessed via local storage paths. The exploitation method relies on supplying malformed input data within a PowerPoint file that bypasses boundary checks or forces the application to return sensitive memory contents or local file data through error handling mechanisms or UI rendering anomalies. During the attack flow, the adversary crafts a malicious presentation file designed to exploit the input validation weakness. Upon opening the file, Microsoft Office PowerPoint parses the malicious structures without adequate validation, causing the application to process inputs that trigger the disclosure routine. The payload behavior involves leaking targeted data structures or local file contents back to the attacker or exposing them within the application interface or temporary log files. The post-exploitation impact is characterized by localized information disclosure, allowing the unauthorized retrieval of sensitive information residing on the host system, which can subsequently be leveraged for secondary exploitation phases or privilege escalation maneuvers."
}
CVE-2026-70320: Microsoft Office PowerPoint Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere