ZeroHour

CVE-2026-69767

mass

Use-After-Free RCE in Microsoft PowerPoint (Office 2019/2021/2024 & Microsoft 365)

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69767 is a use-after-free (CWE-416) memory-safety flaw in Microsoft Office PowerPoint that an unauthenticated remote attacker can exploit to execute code. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the attacker needs no credentials but must rely on user interaction, consistent with the victim opening or previewing a specially crafted PowerPoint file such as an email attachment or downloaded deck; the freed-then-reused memory is then corrupted in a way the attacker can leverage. Successful exploitation yields remote code execution with high impact on confidentiality, integrity and availability, running with the privileges of the user who opened the file. Affected deployments include Microsoft 365 Apps and Microsoft 365, plus the perpetual Office 2019, Office 2021 and Office 2024 editions that include PowerPoint. As of the September 2026 Patch Tuesday advisory there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.8% probability of exploitation within 30 days (55th percentile).

What to do: Apply Microsoft's September 2026 Patch Tuesday Office/PowerPoint security updates to Microsoft 365 Apps and Office 2019/2021/2024 deployments, prioritizing workstations that open untrusted files, and verify installed Office build numbers against Microsoft's advisory. Until patched, discourage opening PowerPoint files from untrusted sources and rely on Protected View, email attachment sandboxing and Attack Surface Reduction rules as interim mitigations. No exploit or in-the-wild activity is known, so standard patch-cycle cadence is reasonable, but treat the 8.8 severity as a priority within the month.

Affected
Microsoft 365 Apps (PowerPoint component)
Microsoft 365 (PowerPoint component)
Microsoft Office 2019 (PowerPoint component)
Microsoft Office 2021 (PowerPoint component)
Microsoft Office 2024 (PowerPoint component)
Microsoft PowerPointStandalone/PowerPoint CPE listed by the CVE; affected build ranges per Microsoft's September 2026 advisory
Estimated exposure
masshundreds of millions of users/devices (Office and PowerPoint are bundled across enterprise and consumer installs of Microsoft 365 and perpetual Office… — Microsoft 365 alone is deployed on hundreds of millions of paid seats and PowerPoint ships with every affected edition, so the potentially exposed install base plausibly exceeds one million users by orders of magnitude; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, microsoft 365, office 2019, office 2021, office 2024, powerpoint
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.