LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2010-2572: Microsoft PowerPoint Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2010-2572 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.

CVE-2010-2572 is a buffer overflow vulnerability in Microsoft PowerPoint that can allow remote code execution. For IT and security teams, this matters because a crafted PowerPoint file can be used to run attacker-controlled code in the context of the user who opens it, potentially leading to further compromise of the endpoint or broader environment. Specifics such as exact affected builds must be confirmed against the vendor advisory.

CISA summarizes the issue as a buffer overflow that enables remote code execution and directs organizations to apply updates per vendor instructions. Ransomware use is not documented for this CVE.

How it works

This vulnerability falls under CWE-119: improper restriction of operations within the bounds of a memory buffer. In products like Microsoft PowerPoint, buffer overflows typically arise when the application parses a file or object and writes more data into a fixed-size buffer than it can hold. Excess data can overwrite adjacent memory, which an attacker may leverage to alter program control flow.

An attacker abuses the flaw by supplying a specially crafted PowerPoint document. When a user opens that file in a vulnerable PowerPoint instance, the overflow can lead to execution of code chosen by the attacker, running with the privileges of the logged-in user. Exact exploit mechanics and preconditions are not detailed in the provided facts; treat any public proof-of-concept claims cautiously and validate behavior only against the official vendor advisory and your own controlled testing.

Am I affected? How to find it in your systems

Microsoft PowerPoint is commonly installed as part of Microsoft Office on Windows desktops and laptops used for document creation and review. It may also appear on terminal servers, VDI images, and shared workstations. Inventory should cover both interactive user machines and any automated systems that open or convert PowerPoint files.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2010-2572 exactly as described in the vendor advisory and CISA’s required action to apply updates per vendor instructions. Confirm successful installation through your patch-management reporting and re-inventory afterward.

If you can't patch immediately

When immediate patching is blocked by change windows or compatibility testing, reduce exposure with compensating controls while you schedule the update.

If your data may have been exposed

Actively exploited client-side remote-code-execution vulnerabilities can be a stepping stone to broader intrusion and data theft, even when ransomware use is not documented for the specific CVE. If you have indicators that a vulnerable PowerPoint instance processed a malicious file, follow your incident-response process: isolate the host, preserve evidence, and hunt for lateral movement and credential access. As a further check on whether associated identities have appeared in known breach corpora, you can run a free exposure scan of your email addresses against published breach data and then enforce credential resets and MFA where warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · PowerPoint
WeaknessCWE-119
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities