CVE-2026-70322: Powerpoint Information Disclosure Vulnerability
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
Other sources
Powerpoint Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.112.26081010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70322?
The severity of CVE-2026-70322 is rated medium with a score of 5.5.
What type of vulnerability is identified in CVE-2026-70322?
CVE-2026-70322 is an information disclosure vulnerability due to improper input validation in Microsoft PowerPoint.
Which Microsoft software is affected by CVE-2026-70322?
CVE-2026-70322 affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, and Microsoft Office LTSC 2021 and 2024 for both Windows and Mac.
How can organizations mitigate the risks associated with CVE-2026-70322?
Organizations can mitigate the risks of CVE-2026-70322 by applying the latest updates and patches provided by Microsoft.
Can CVE-2026-70322 be exploited remotely?
CVE-2026-70322 requires local access to the affected system, making it less likely to be exploited remotely.