110 results (0.008 seconds)

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

18 Dec 2024 — A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions. Existe una vulnerabilidad de inyección de librería en Microsoft PowerPoint 16.83 para macOS. Una librería especialmente manipulada puede aprovechar los privilegios... • https://talosintelligence.com/vulnerability_reports/TALOS-2024-1974 • CWE-347: Improper Verification of Cryptographic Signature •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

13 Aug 2024 — Microsoft PowerPoint Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PPTX files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can le... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38171 • CWE-416: Use After Free •

CVSS: 7.8EPSS: 1%CPEs: 9EXPL: 0

13 Feb 2024 — Microsoft Office Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de Microsoft Office • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20673 • CWE-693: Protection Mechanism Failure •

CVSS: 9.3EPSS: 0%CPEs: 26EXPL: 0

15 Apr 2022 — Windows Graphics Component Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota en Windows Graphics Component • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26903 •

CVSS: 7.8EPSS: 11%CPEs: 6EXPL: 0

11 Mar 2021 — Microsoft PowerPoint Remote Code Execution Vulnerability Una Vulnerabilidad de Ejecución de Código Remota de Microsoft PowerPoint This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PowerPoint presentation files. The issue results from the lack of validating the... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27056 •

CVSS: 9.3EPSS: 2%CPEs: 6EXPL: 0

09 Dec 2020 — Microsoft PowerPoint Remote Code Execution Vulnerability Vulnerabilidad de ejecución de código remota en Microsoft PowerPoint This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerPoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PowerPoint presentation files. The issue results from the lack of validating the exi... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17124 •

CVSS: 8.8EPSS: 37%CPEs: 33EXPL: 0

15 Apr 2020 — A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991. Hay una vulnerabilidad de ejecución de código remota cuando Microsoft Office carga inapropiadamente bibliotecas de tipos arbitrarios, también se conoce como "Microsoft Office Remote Code Execution Vulnerability". Este ID de CVE es diferente de CVE-2020-0991. • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0760 •

CVSS: 9.3EPSS: 21%CPEs: 7EXPL: 0

10 Dec 2019 — A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. Hay una vulnerabilidad de ejecución de código remota en el software Microsoft PowerPoint cuando el software no puede manejar apropiadamente los objetos en memoria, también se conoce como "Microsoft PowerPoint Remote Code Execution Vulnerability". This vulnerability allows remote attackers to execute arbitra... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1462 • CWE-908: Use of Uninitialized Resource •

CVSS: 5.5EPSS: 8%CPEs: 9EXPL: 0

05 Mar 2019 — A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'. Existe una vulnerabilidad de omisión de la característica de seguridad cuando Microsoft Office no valida las URL. Un atacante podría enviar un archivo especialmente manipulado a una víctima, lo que podría engañarlo para que introduzca sus crede... • http://www.securityfocus.com/bid/106863 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 9.3EPSS: 33%CPEs: 15EXPL: 0

12 Dec 2018 — A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft SharePoint Server. Existe una vulnerabilidad de ejecución remota de código en el software de Microsoft PowerPoint cuando no gestiona correctamente objet... • http://www.securityfocus.com/bid/106104 •