ZeroHour

CVE-2026-80081

mass

Use-After-Free RCE in Microsoft Office PowerPoint (Microsoft 365 Apps)

CVSS 3.1
8.8 high
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-80081 is a use-after-free memory-corruption flaw (CWE-416) in the PowerPoint component of Microsoft 365 Apps that allows an unauthenticated attacker to execute code over a network. Exploitation requires user interaction (CVSS UI:R): the attacker must deliver a specially crafted PowerPoint file, typically via email or a shared location, and convince the victim to open or preview it, after which malicious code runs with the victim user's privileges. A successful attack yields code execution on the endpoint with the user's rights, with high impact to confidentiality, integrity, and availability, and can serve as a foothold for data theft or lateral movement. Any user or organization running Microsoft 365 Apps with PowerPoint is affected; the source data does not specify affected version ranges, so Microsoft's advisory must be consulted for exact builds. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.5% probability of exploitation within 30 days (40th percentile), indicating no confirmed in-the-wild exploitation yet.

What to do: Deploy the Microsoft 365 Apps security update addressing CVE-2026-80081 from Microsoft's advisory as soon as practical (specific fixed builds are not provided in this data), prioritizing endpoints where users routinely open untrusted documents. Until patched, treat unsolicited PowerPoint files as untrusted via attachment filtering, user warnings, and disabling preview of untrusted files. Because exploitation requires user interaction to open a crafted file, attachment filtering and user awareness are the primary interim mitigations.

Affected
Microsoft 365 Apps (PowerPoint component)
Estimated exposure
mass≈100M+ users/devices (Microsoft 365 Apps is the default Office deployment across most Microsoft 365 tenants) — Microsoft 365 Apps is Microsoft's standard Office client, deployed to the hundreds of millions of Microsoft 365 seats Microsoft publicly reports, so any unpatched installation with the PowerPoint component is plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.