Out-of-bounds read in Microsoft products - CVE-2026-72975

 

Out-of-bounds read in Microsoft products - CVE-2026-72975

Published: September 9, 2026


Vulnerability identifier: #VU148120
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72975
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an out-of-bounds read in Microsoft Office PowerPoint when processing a PowerPoint file. A remote attacker can cause PowerPoint to process a file to disclose information.

The Preview Pane is an attack vector, and successful exploitation could expose small portions of heap memory.


Affected software

Microsoft 365 Apps for Enterprise
Microsoft PowerPoint
Microsoft Office

How to mitigate CVE-2026-72975

Install security update from vendor's website.

Microsoft 365 Apps for Enterprise - update to 16.0.20326.20138
Microsoft PowerPoint - update to 16.0.5569.1000
Microsoft Office - addressed in versions 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976

External References

Related Security Bulletins