Microsoft
Microsoft Powerpoint: vulnerabilidades y CVE
Microsoft Powerpoint tiene 86 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 1 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE86
Últimos 12 meses17
Críticas1
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-0556 | Alta (8.8) | 67% | ⚠ Explotación activa | 3 abr 2009 | Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom… |
| CVE-2007-0671 | Alta (8.8) | 43% | ⚠ Explotación activa | 3 feb 2007 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as… |
| CVE-2010-2572 | Alta (7.8) | 59% | ⚠ Explotación activa | 10 nov 2010 | Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability." |
| CVE-2015-2424 | Alta (8.8) | 40% | ⚠ Explotación activa | 14 jul 2015 | Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78513 | Media (5.5) | 0.54% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
| CVE-2026-72977 | Media (6.5) | 0.97% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-72975 | Media (6.5) | 0.92% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-69797 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69767 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69678 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-68809 | Media (5.5) | 0.43% | — | 11 ago 2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
| CVE-2026-55123 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-55120 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-55043 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-45649 | Alta (7.1) | 0.44% | — | 9 jun 2026 | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-44812 | Alta (7.8) | 0.47% | — | 9 jun 2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
| CVE-2026-44803 | Alta (7.8) | 0.47% | — | 9 jun 2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
| CVE-2026-41102 | Media (5.5) | 0.31% | — | 12 may 2026 | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. |
| CVE-2026-32200 | Alta (7.8) | 0.47% | — | 14 abr 2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2026-26133 | Alta (7.1) | 0.54% | — | 16 mar 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-59238 | Alta (7.8) | 0.38% | — | 14 oct 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-54908 | Alta (7.8) | 0.60% | — | 9 sept 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-53761 | Alta (7.8) | 0.52% | — | 12 ago 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-49705 | Alta (7.8) | 0.41% | — | 8 jul 2025 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2025-49699 | Alta (7) | 0.35% | — | 8 jul 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47175 | Alta (7.8) | 2.4% | — | 10 jun 2025 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
| CVE-2024-39804 | Crítica (9.1) | 0.89% | — | 18 dic 2024 | A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could… |
| CVE-2024-38171 | Alta (7.8) | 0.93% | — | 13 ago 2024 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2024-20673 | Alta (7.8) | 1.2% | — | 13 feb 2024 | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2022-26903 | Alta (7.8) | 2.7% | — | 15 abr 2022 | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2021-27056 | Alta (7.8) | 4.3% | — | 11 mar 2021 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2020-17124 | Alta (7.8) | 3.5% | — | 10 dic 2020 | Microsoft PowerPoint Remote Code Execution Vulnerability |
| CVE-2020-0760 | Alta (8.8) | 8.8% | — | 15 abr 2020 | A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991. |
| CVE-2019-1462 | Alta (7.8) | 18% | — | 10 dic 2019 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.