
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-47175 is a use-after-free vulnerability in Microsoft Office PowerPoint that allows an unauthorized attacker to execute arbitrary code locally. It affects Microsoft PowerPoint 2016, Office 2019, Office 2021, Office 2024, Office LTSC 2021/2024 (Windows and macOS), and Microsoft 365 Apps for Enterprise. The vulnerability was disclosed and patched on June 10, 2025, as part of Microsoft's June 2025 Patch Tuesday. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, ENISA EUVD).
The root cause is a use-after-free condition (CWE-416) in Microsoft Office PowerPoint's file parsing or object handling logic. An attacker exploits this by crafting a malicious PowerPoint file that, when opened by a victim, triggers the use of freed memory, enabling arbitrary code execution in the context of the current user. The attack vector is local (the file must be opened on the target system), requires no privileges, but does require user interaction — specifically, a user opening a malicious .pptx or similar file. A proof-of-concept exploit was publicly released on GitHub in March 2026, and an Exploit-DB entry (EDB-ID:52351) was published in July 2025 (MSRC Advisory, PoC GitHub, Exploit-DB).
Successful exploitation allows an attacker to execute arbitrary code on the victim's system with the privileges of the logged-in user, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, including data theft, installation of malware or backdoors, and disruption of system availability. Because user interaction is required (opening a malicious file), the most likely attack scenario involves phishing or social engineering to deliver the malicious PowerPoint document (MSRC Advisory, ENISA EUVD).
A public proof-of-concept exploit is available on GitHub (published March 2026) and an Exploit-DB entry (EDB-ID:52351) exists as of July 2025, increasing the risk of weaponization (PoC GitHub, Exploit-DB). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.06%, indicating a currently low but non-negligible probability of exploitation. CVE-2025-47175 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (ENISA EUVD).
.pptx file that triggers the memory corruption condition in PowerPoint's object handling routines upon opening.%TEMP%, %APPDATA%, or startup folders following the opening of a PowerPoint file; suspicious .pptx files received via email or downloaded from untrusted sources.POWERPNT.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe, or network utilities like curl.exe or certutil.exe).POWERPNT.EXE or processes spawned by it to external IP addresses or domains shortly after a PowerPoint file is opened.POWERPNT.EXE as the parent process for unusual child processes; application crash logs or Dr. Watson/WER reports related to PowerPoint around the time of suspected exploitation.Microsoft released patches on June 10, 2025 as part of the June 2025 Patch Tuesday update. Specific fixed versions include PowerPoint 2016 (16.0.5504.1000 or later), Office LTSC for Mac 2021/2024 (16.98.25060824 or later), and updates for Office 2019, Office LTSC 2021/2024 (Windows), and Microsoft 365 Apps for Enterprise via the standard update channel. Organizations should apply the June 2025 security updates immediately, prioritizing systems running PowerPoint 2016, Office 2019, and Office LTSC versions. As a temporary workaround, restrict users from opening PowerPoint files from untrusted or unknown sources, and consider enabling Protected View for files received from the internet (MSRC Advisory, ENISA EUVD).
CVE-2025-47175 was covered as part of broader June 2025 Patch Tuesday reporting by multiple security outlets. Bleeping Computer, Rapid7, Zero Day Initiative (ZDI), and Sophos all included it in their Patch Tuesday roundups, noting it as one of 66–67 vulnerabilities addressed that month (BleepingComputer, Rapid7 Blog, ZDI Blog, Sophos News). Community discussion highlighted the public PoC availability as a concern, with some forums noting the potential for phishing-based exploitation of the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."