First published: Wed Dec 18 2024(Updated: )
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft PowerPoint 2010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39804 is rated as a high severity vulnerability due to its potential for privilege escalation and permission bypass.
To mitigate CVE-2024-39804, it is recommended to apply the latest security updates for Microsoft PowerPoint as soon as they are available.
CVE-2024-39804 specifically affects Microsoft PowerPoint 16.83 for macOS.
CVE-2024-39804 allows for injection of a malicious library that can exploit PowerPoint's access privileges.
CVE-2024-39804 was reported by security researchers from Cisco Talos.