CVE-2026-70320

365_apps: Improper Input Validation (CVE-2026-70320)

Beschreibung

Ungültige Eingabeverarbeitung in Microsoft Office PowerPoint ermöglicht es einem nicht autorisierten Angreifer, lokal Informationen offenzulegen.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
5.5
Quelle: nvd-v3
30.9 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-11 17:05 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-11 22:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-70320","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-08-11 17:19 UTC· secure@microsoft.com
    • Affected: Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac (+4)
    • Description: Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
    • CVSS V3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
    • CWE: CWE-20

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • microsoft

    365_apps

  • microsoft

    microsoft_365

  • microsoft

    office_2019

  • microsoft

    office_2021

  • microsoft

    office_2024

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-70320