« Volver al listado

Microsoft

Microsoft Powerpoint: vulnerabilidades y CVE

Microsoft Powerpoint tiene 86 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 1 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE86
Últimos 12 meses17
Críticas1
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2009-0556Alta (8.8)67%⚠ Explotación activa3 abr 2009
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom…
CVE-2007-0671Alta (8.8)43%⚠ Explotación activa3 feb 2007
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as…
CVE-2010-2572Alta (7.8)59%⚠ Explotación activa10 nov 2010
Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
CVE-2015-2424Alta (8.8)40%⚠ Explotación activa14 jul 2015
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-78513Media (5.5)0.54%—8 sept 2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-72977Media (6.5)0.97%—8 sept 2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-72975Media (6.5)0.92%—8 sept 2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
CVE-2026-69797Alta (8.8)0.82%—8 sept 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-69767Alta (8.8)0.82%—8 sept 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-69678Alta (8.8)0.82%—8 sept 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-68809Media (5.5)0.43%—11 ago 2026
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-55123Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55120Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55043Alta (7.8)0.47%—14 jul 2026
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-45649Alta (7.1)0.44%—9 jun 2026
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
CVE-2026-44812Alta (7.8)0.47%—9 jun 2026
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-44803Alta (7.8)0.47%—9 jun 2026
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-41102Media (5.5)0.31%—12 may 2026
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
CVE-2026-32200Alta (7.8)0.47%—14 abr 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-26133Alta (7.1)0.54%—16 mar 2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2025-59238Alta (7.8)0.38%—14 oct 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-54908Alta (7.8)0.60%—9 sept 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-53761Alta (7.8)0.52%—12 ago 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-49705Alta (7.8)0.41%—8 jul 2025
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-49699Alta (7)0.35%—8 jul 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47175Alta (7.8)2.4%—10 jun 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2024-39804Crítica (9.1)0.89%—18 dic 2024
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could…
CVE-2024-38171Alta (7.8)0.93%—13 ago 2024
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2024-20673Alta (7.8)1.2%—13 feb 2024
Microsoft Office Remote Code Execution Vulnerability
CVE-2022-26903Alta (7.8)2.7%—15 abr 2022
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2021-27056Alta (7.8)4.3%—11 mar 2021
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2020-17124Alta (7.8)3.5%—10 dic 2020
Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2020-0760Alta (8.8)8.8%—15 abr 2020
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
CVE-2019-1462Alta (7.8)18%—10 dic 2019
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter4
  2. T1203 Exploitation for Client Execution4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft