CVE-2026-32200: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
Other sources
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5548.1001Patch KB5002808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32200?
CVE-2026-32200 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2026-32200?
To mitigate CVE-2026-32200, you should apply the latest security updates provided by Microsoft for the affected versions of Office.
What products are affected by CVE-2026-32200?
CVE-2026-32200 affects several Microsoft PowerPoint versions including Office 2019, Office LTSC 2021, Office LTSC 2024, and PowerPoint 2016.
Can CVE-2026-32200 be exploited by attackers?
Yes, CVE-2026-32200 can be exploited by an unauthorized attacker to execute code locally on vulnerable systems.
What type of vulnerability is CVE-2026-32200?
CVE-2026-32200 is a use after free vulnerability in Microsoft PowerPoint.