Skip to content
COOEY

FAIL › dossier

PowerPoint

PRODUCT

· dossier confidence 85%

PowerPoint is a Microsoft presentation application with a documented history of high-severity remote code execution vulnerabilities. Recent and historical evidence shows repeated RCE flaws, including memory corruption and buffer overflows, some of which have been actively exploited in the wild and require urgent patching.

PROFILE
CategoryproductWhat they doPowerPoint is a presentation software application developed by Microsoft.
SECURITY POSTURE

PowerPoint has a history of high-severity remote code execution (RCE) vulnerabilities, including memory corruption and buffer overflow flaws that have been actively exploited in the wild. Recent evidence indicates ongoing RCE issues requiring urgent patching via Office updates.

Notable failures
  • CVE-2015-2424: Memory corruption RCE
  • CVE-2010-2572: Buffer overflow RCE exploited in the wild
  • CVE-2026-70313: RCE requiring Office updates
  • CVE-2026-70325: RCE requiring August Office updates
Patterns: repeated unpatched RCE vulnerabilities; memory corruption and buffer overflow flaws; active exploitation in the wild
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-03 CVE-2015-2424 high A memory corruption flaw in PowerPoint allowed remote attackers to execute arbitrary code via a crafted document.
2022-06-08 CVE-2010-2572 high A Microsoft PowerPoint buffer overflow vulnerability allows for remote code execution and is currently being exploited in the wild.
Open questions: PowerPoint's current patching cadence for RCE vulnerabilities · Whether Microsoft has implemented mitigations for the CVE-2010-2572 exploit
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-17 03:48:57.456364+00:00