Sceawere

Vulnerability Detail

CVE-2026-70322UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office PowerPoint Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft 365 Apps for Enterprise
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:19:09.877Z",
  "pubdate": "2026-08-11T17:19:09.877Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw within Microsoft Office PowerPoint, which enables an unauthorized threat actor to execute local information disclosure attacks. The primary security impact is the unauthorized extraction of sensitive local data residing on the host system, compromising confidentiality.\nThe affected product is Microsoft Office PowerPoint. The risk implications are moderate to high depending on the sensitivity of the exposed local files and the security posture of the host environment. The vulnerability stems from insufficient sanitization and validation of untrusted inputs processed by the application.\nRegarding attacker capabilities, an unauthorized malicious actor with local or targeted delivery vector access can exploit the flaw without requiring prior authentication. Exploitation requirements typically involve tricking a user into opening a maliciously crafted PowerPoint file or leveraging a composite attack chain where improperly validated inputs trigger unauthorized file system access or memory state reading.\nBecause the vulnerability facilitates unauthorized local information disclosure, successful exploitation grants the adversary visibility into sensitive assets, potentially exposing credentials, configuration files, or proprietary user data. Organizations utilizing vulnerable versions of Microsoft Office PowerPoint face elevated risks of data exfiltration if mitigating controls or security updates are not applied.",
  "technicalDetails": "The root cause of the vulnerability resides in improper input validation logic within the Microsoft Office PowerPoint parsing engine. When processing specially crafted presentations, the application fails to adequately sanitize or bound-check specific structural elements or embedded parameters. This parsing deficiency creates a flaw within the vulnerable component responsible for handling internal file references or document structures.\nFrom an exploitation perspective, the attack flow begins when an unauthorized adversary supplies a malformed PowerPoint file to a target system. When the user or an automated process opens the file, the parsing engine attempts to process the improperly validated inputs. Due to the lack of strict input verification, the application interprets the malicious input in an unintended manner, leading to the unauthorized exposure of local data structures or file contents.\nThe vulnerability requires no authentication and can be triggered locally or via standard document delivery vectors. Privilege requirements are minimal, typically aligning with the standard user context running the Microsoft Office PowerPoint application. Network exposure is generally indirect, as exploitation relies on the consumption of a crafted file rather than direct network-based remote code execution primitives.\nThe payload behavior is focused strictly on information disclosure rather than direct code execution or denial of service. Upon successful processing of the crafted input, the application leaks internal memory contents or grants unauthorized read access to local files accessible to the user context. Post-exploitation impact includes the potential aggregation of sensitive local information, which the attacker can leverage to plan subsequent phases of an intrusion, such as privilege escalation or lateral movement using harvested credentials or internal system metadata."
}
CVE-2026-70322: Microsoft Office PowerPoint Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere