CVE-2026-77898 – Microsoft Office PowerPoint Remote Code Execution Vulnerability
CVSS 7.5
IMPORTANT
Critical - Same Day Deployment
“A malicious PowerPoint interaction could turn a memory error into remote code execution, putting sensitive data and systems at risk.”
CVE-2026-77898 is a critical heap-based buffer overflow vulnerability in Microsoft Office PowerPoint that can allow an unauthorized attacker to execute code over a network. Exploitation requires no privileges but does require user interaction and has high attack complexity. Successful exploitation could have a high impact on confidentiality, integrity, and availability.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.