CVE-2026-72975: Microsoft Office PowerPoint Information Disclosure Vulnerability
Microsoft Office PowerPoint Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002920 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20976 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20207
Event History
Frequently Asked Questions
What interaction does exploitation require?
The attacker does not need prior privileges and can exploit the issue over a network, but user interaction is required. The provided data does not specify the form of interaction.
What is the impact if the vulnerability is exploited?
Successful exploitation can disclose information from the affected PowerPoint application. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
Which PowerPoint deployments are identified as affected?
The listed affected products include PowerPoint 2016, Microsoft 365 Apps for Enterprise, Office 365 for Mac, Office LTSC for Mac 2021 and 2024, and Office LTSC 2021 and 2024 for specified Windows 32-bit or 64-bit editions.