
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49705 is a heap-based buffer overflow vulnerability in Microsoft Office PowerPoint that allows an unauthorized local attacker to execute arbitrary code. It was disclosed on July 8, 2025, as part of Microsoft's July 2025 Patch Tuesday security update cycle. Affected products include Microsoft PowerPoint 2016, Microsoft Office 2019, Office 2021, Office 2024, Office LTSC 2021/2024 (Windows and macOS), and Microsoft 365 Apps for Enterprise. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), where insufficient bounds checking during the processing of a maliciously crafted PowerPoint file leads to memory corruption in the heap. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted PowerPoint file, making this a file-based attack vector (AV:L). No privileges are required by the attacker prior to exploitation. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Microsoft MSRC, Feedly).
Successful exploitation of CVE-2025-49705 results in high impact to confidentiality, integrity, and availability of the affected system. An attacker who tricks a user into opening a malicious PowerPoint file could execute arbitrary code in the context of the current user, potentially gaining unauthorized access to sensitive data, modifying system resources, or causing application crashes. If the victim is running with elevated privileges, the attacker could achieve broader system compromise (Microsoft MSRC).
As of the July 8, 2025 disclosure, there is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit for CVE-2025-49705. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.058%, indicating a low probability of exploitation in the near term. Microsoft has assessed the exploit code maturity as "Unproven" (Microsoft MSRC, Feedly).
%TEMP%, %APPDATA%) by the PowerPoint process.POWERPNT.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe); unexpected network connections initiated by POWERPNT.EXE.POWERPNT.EXE (Event ID 1000/1001); Windows Error Reporting entries referencing heap corruption in Office modules.Microsoft released security updates on July 8, 2025 to address this vulnerability. Users should apply the latest Office security updates immediately via Windows Update or the Microsoft Update Catalog. For PowerPoint 2016 specifically, the fixed version is 16.0.5508.1000 or later. Additional mitigations include enabling Protected View for files from unknown or untrusted sources, exercising caution when opening PowerPoint files from external sources, and ensuring Microsoft Defender or equivalent endpoint protection is active with up-to-date definitions (Microsoft MSRC).
The vulnerability was covered as part of broader July 2025 Patch Tuesday roundups by security outlets including BleepingComputer, Rapid7, Sophos, and Zero Day Initiative (ZDI), which collectively noted the large patch volume (137 vulnerabilities) in that cycle. Office-Watch highlighted the PowerPoint heap overflow as a notable concern among the July Office updates. No specific researcher commentary or threat actor attribution has been published regarding this CVE (BleepingComputer, ZDI, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."