ZDI-CAN-25090: ZDI-24-1511: Microsoft Office PowerPoint PPTX File Parsing Use-After-Free Remote Code Execution Vulnerability
Published Nov 14, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-49032.
Affected Software
1 affected component
Microsoft Office PowerPoint
Event History
Nov 14, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-25090?
The severity of ZDI-CAN-25090 is high due to its potential for remote code execution.
2
How do I fix ZDI-CAN-25090?
To fix ZDI-CAN-25090, ensure that Microsoft Office PowerPoint is updated to the latest security patch.
3
What software is affected by ZDI-CAN-25090?
ZDI-CAN-25090 affects Microsoft Office PowerPoint installations.
4
How can ZDI-CAN-25090 be exploited?
ZDI-CAN-25090 can be exploited when a user interacts with malicious pages or files.
5
What type of vulnerability is ZDI-CAN-25090?
ZDI-CAN-25090 is a remote code execution vulnerability.