Microsoft Powerpoint vulnerabilities
74 known vulnerabilities affecting microsoft/powerpoint.
Total CVEs
74
CISA KEV
4
actively exploited
Public exploits
10
Exploited in wild
6
Severity breakdown
CRITICAL24HIGH40MEDIUM9LOW1
Vulnerabilities
Page 3 of 4
CVE-2017-8743P3HIGHCVSS 7.8v20162017-09-13
CVE-2017-8743 [HIGH] CVE-2017-8743: A remote code execution vulnerability exists in Microsoft PowerPoint 2016, Microsoft SharePoint Ente
A remote code execution vulnerability exists in Microsoft PowerPoint 2016, Microsoft SharePoint Enterprise Server 2016, and Office Online Server when they fail to properly handle objects in memory, aka "PowerPoint Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8742.
nvd
CVE-2017-8513P3HIGHCVSS 7.8v20072017-06-15
CVE-2017-8513 [HIGH] CWE-119 CVE-2017-8513: A remote code execution vulnerability exists in Microsoft PowerPoint when the software fails to prop
A remote code execution vulnerability exists in Microsoft PowerPoint when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability".
nvd
CVE-2006-5296P4MEDIUMCVSS 4.3PoCv20032006-10-16
CVE-2006-5296 [MEDIUM] CVE-2006-5296: PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-200
nvd
CVE-2008-3068P3HIGHCVSS 7.5v2003v20072008-07-07
CVE-2008-3068 [HIGH] CVE-2008-3068: Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan
nvd
CVE-2026-55120P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55120 [HIGH] CWE-122 CVE-2026-55120: Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55123P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55123 [HIGH] CWE-122 CVE-2026-55123: Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55043P3HIGHCVSS 7.8v20162026-07-14
CVE-2026-55043 [HIGH] CWE-122 CVE-2026-55043: Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59238P3HIGHCVSS 7.8v20162025-10-14
CVE-2025-59238 [HIGH] CWE-416 CVE-2025-59238: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-32200P3HIGHCVSS 7.8v20162026-04-14
CVE-2026-32200 [HIGH] CWE-416 CVE-2026-32200: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54908P3HIGHCVSS 7.8v20162025-09-09
CVE-2025-54908 [HIGH] CWE-416 CVE-2025-54908: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53761P3HIGHCVSS 7.8v20162025-08-12
CVE-2025-53761 [HIGH] CWE-416 CVE-2025-53761: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3279P3MEDIUMCVSS 5.5v2010v20132016-07-13
CVE-2016-3279 [MEDIUM] CWE-254 CVE-2016-3279: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, Power
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via
nvd
CVE-2025-49705P3HIGHCVSS 7.8v20162025-07-08
CVE-2025-49705 [HIGH] CWE-122 CVE-2025-49705: Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2006-0022P3HIGHCVSS 7.6v2000v2002+2 more2006-06-13
CVE-2006-0022 [HIGH] CVE-2006-0022: Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Offic
Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v2000v2002+2 more2006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2020-17124P3HIGHCVSS 7.8v2010v2013+1 more2020-12-10
CVE-2020-17124 [HIGH] CVE-2020-17124: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
nvd
CVE-2021-27056P3HIGHCVSS 7.8v2010v2013+1 more2021-03-11
CVE-2021-27056 [HIGH] CVE-2021-27056: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
nvd
CVE-2004-0848P3HIGHCVSS 7.5v20022005-02-08
CVE-2004-0848 [HIGH] CVE-2004-0848: Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
nvd
CVE-2006-3656P4LOWCVSS 2.6PoCv20032006-07-18
CVE-2006-3656 [LOW] CVE-2006-3656: Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memor
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possi
nvd
CVE-2024-38171P3HIGHCVSS 7.8v20162024-08-13
CVE-2024-38171 [HIGH] CWE-416 CVE-2024-38171: Microsoft PowerPoint Remote Code Execution Vulnerability
Microsoft PowerPoint Remote Code Execution Vulnerability
nvd