CVE-2025-49705: Microsoft PowerPoint Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Other sources
Microsoft PowerPoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49705?
CVE-2025-49705 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-49705?
To fix CVE-2025-49705, users should apply the latest security updates provided by Microsoft for affected versions of PowerPoint.
Which versions of PowerPoint are affected by CVE-2025-49705?
CVE-2025-49705 affects Microsoft PowerPoint 2016, Office LTSC 2021, Office LTSC 2024, and several versions of Microsoft 365 Apps.
What type of vulnerability is CVE-2025-49705?
CVE-2025-49705 is a heap-based buffer overflow vulnerability that can allow unauthorized attackers to execute code locally.
Are there any workarounds for CVE-2025-49705?
Until a patch is applied, users should limit the use of affected software and avoid opening untrusted presentation files.