Use-after-free in Microsoft 365 Apps for Enterprise - CVE-2026-80081
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Office PowerPoint when processing a specially crafted PowerPoint presentation containing malicious linked media. A remote attacker can send a specially crafted PowerPoint presentation to a target user to execute arbitrary code.
The victim must open the presentation, start the slideshow, and allow the linked content; the Preview Pane is not an attack vector.