Sceawere
Vulnerability Detail
CVE-2026-70325UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft Office PowerPoint Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Microsoft 365 Apps for Enterprise
- Attack Type
- CWE-20: Improper Input Validation
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-08-11T17:19:10.270Z",
"pubdate": "2026-08-11T17:19:10.270Z",
"executiveSummary": "This vulnerability involves an improper input validation flaw within Microsoft Office PowerPoint, which enables an unauthorized threat actor to execute local information disclosure attacks.\nThe primary security impact is the unauthorized exposure of sensitive local data residing on the host system to the adversary.\nThe affected product is Microsoft Office PowerPoint, specifically within components responsible for parsing input data and rendering presentation files.\nThe risk implications are centered around the breach of confidentiality, where local file contents or system memory structures can be exposed through crafted file processing.\nTo exploit this vulnerability, an attacker requires the capability to craft malicious input parameters or presentation structures and deliver them to a victim user or system.\nExploitation requirements typically involve tricking a target into opening a specially crafted PowerPoint file, resulting in the improper validation routine triggering the information leak.",
"technicalDetails": "The root cause of the vulnerability stems from insufficient or absent input validation checks within the Microsoft Office PowerPoint parser when processing specific file structures or object properties.\nWhen the vulnerable component parses a maliciously crafted input, it fails to adequately sanitize or bound-check the data, leading to anomalous memory handling or unintended file reference resolution.\nThe exploitation method relies on supplying malformed data fields within a document that forces the application to read from unauthorized memory locations or local file system resources.\nThe attack flow proceeds as follows: First, the adversary crafts a specialized PowerPoint document containing malicious input vectors designed to target the validation weakness. Second, the victim opens the malicious file utilizing a vulnerable installation of Microsoft Office PowerPoint. Third, the application processes the input data without proper sanitization, invoking internal functions that handle the payload incorrectly. Fourth, the improper handling results in the leakage of local information, which can be exfiltrated or referenced in subsequent stages by the attacker.\nThe vulnerable component resides within the core parsing and rendering engine of Microsoft Office PowerPoint.\nRegarding authentication and privilege requirements, the vulnerability can be exploited locally by an unauthorized attacker, typically requiring the user to interact with or open the malicious file, operating under the context of the locally logged-in user standard privileges.\nNetwork exposure is not strictly required for local file disclosure vectors, as the attack vector relies on local file processing, though delivery of the payload may occur via external channels such as email or web downloads.\nThe post-exploitation impact includes the localized breach of sensitive data, potentially exposing internal system configurations, user data, or memory contents that could facilitate further compromise."
}