← Vulnerability feed

Vulnerability record · CVE-2010-2572 · published 10 November 2010

CVE-2010-2572: Microsoft PowerPoint buffer overflow via crafted PowerPoint 95 file

Microsoft · Powerpoint

Microsoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can corrupt memory and allow remote code execution in the context of the user. The flaw is a classic buffer overflow (CWE-120) and is listed in CISA's Known Exploited Vulnerabilities catalog.

7.8 CVSS 3.1 High CISA KEV since 8 Jun 2022 EPSS 59% · top 0.9% CWE-120 · Classic buffer overflow
7.8CVSS 3.1 base score, v2 9.3
59%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution, is listed in CISA KEV, and has a very high EPSS score, though exploitation requires user interaction and affects only legacy PowerPoint versions.

What it is

Microsoft PowerPoint 2002 SP3 and 2003 SP3 contain a buffer overflow when parsing a crafted PowerPoint 95 document. Opening the malicious file can corrupt memory and allow remote code execution in the context of the user. The flaw is a classic buffer overflow (CWE-120) and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker who gets a victim to open the crafted document can execute arbitrary code with the privileges of the logged-on user, potentially leading to full system compromise.

Attack surface

The vulnerability is reached locally when a user opens a malicious PowerPoint 95 file; the CVSS vector shows AV:L with UI:R and PR:N, so no authentication is required but user interaction (opening the file) is needed.

Exploitation

CVE-2010-2572 is listed in CISA KEV (added 2022-06-08) and has a high EPSS 30-day probability of 0.626 (99th percentile), indicating observed exploitation activity. No ransomware campaign use is documented in the record.

What to do

  • Apply the Microsoft security update referenced in MS10-088 (patch first).
  • Upgrade or remove unsupported PowerPoint 2002 and 2003 installations.
  • Block or quarantine PowerPoint 95 (.ppt) files at email and web gateways where feasible.
  • Disable or restrict opening of legacy PowerPoint formats via Group Policy or file association controls.
  • Train users not to open unexpected PowerPoint attachments from untrusted sources.

Detection

  • Monitor for PowerPoint processes spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
  • Alert on Office applications loading or writing files from unusual paths (temp, user profile, network shares) after opening a document.
  • Search endpoint logs for crashes or memory corruption events in POWERPNT.EXE tied to document opens.
  • Review email and proxy logs for PowerPoint 95 attachments or downloads matching known exploit indicators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-2572 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft PowerPoint Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2572 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2009-0556Microsoft PowerPoint memory corruption via malformed OutlineTextRefAtomMicrosoft PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and PowerPoint in Office 2004 for Mac mishandle an OutlineTextRefAtom with an invalid index value,…KEVEPSS 67%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%9.3CVE-2015-1682Microsoft excel memory buffer overflow vulnerabilityMicrosoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, O…EPSS 19%9.3CVE-2015-0097Microsoft excel vulnerabilityMicrosoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execut…EPSS 41%9.3CVE-2015-0085Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, Power…EPSS 19%9.3CVE-2011-3396Microsoft powerpoint vulnerabilityUntrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the cur…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2010-2572), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.