Dismissed
(no matching packages found)
Permalink
CVE-2026-72938
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Exploit Code Maturity (E): Unproven (U)
- Remediation Level (RL): Official Fix (O)
- Report Confidence (RC): Confirmed (C)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
Activity log
- Created & dismissed (no matching packages found) suggestion
Microsoft Office PowerPoint Information Disclosure Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
References
Affected products
Microsoft Office 2019
- <16.0.10417.20207
Microsoft Office LTSC 2021
- <16.0.14334.20906
Microsoft Office LTSC 2024
- <16.0.17932.20976
Microsoft Office 365 for Mac
- ==-
Microsoft 365 Apps for Enterprise
- <16.0.20326.20138
Microsoft Office LTSC for Mac 2021
- ==-
Microsoft Office LTSC for Mac 2024
- ==-