CVE-2024-39804 - CVE House
Back to Database
Status published High CVE-2024-39804

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for...

Vulnerability Description

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39804

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Discovered by Francesco Benvenuto of Cisco Talos.

Affected Vendor

Affected Software

PowerPoint
Vulnerable Versions:
16.83 for macOS

Timeline

Official Publish: December 18th, 2024
Last Modified: December 20th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)