EIP-2026-115750

PRE-CVE

Microsoft Office PowerPoint 2010 - MSO/OART Heap Out-of-Bounds Access

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115750. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit demonstrates a time-of-check time-of-use (TOCTOU) vulnerability in Microsoft Office 2010, leading to memory corruption and an access violation. The PoC involves a fuzzed PowerPoint file that triggers unreliable dereferencing of an invalid memory pointer in mso.dll.

Description

Microsoft Office PowerPoint 2010 - MSO/OART Heap Out-of-Bounds Access

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdoswindows
https://www.exploit-db.com/exploits/41418

This exploit demonstrates a time-of-check time-of-use (TOCTOU) vulnerability in Microsoft Office 2010, leading to memory corruption and an access violation. The PoC involves a fuzzed PowerPoint file that triggers unreliable dereferencing of an invalid memory pointer in mso.dll.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Racy
Target: Microsoft Office 2010 (mso.dll 14.0.7173.5000, oart.dll 14.0.7169.5000, ppcore.dll 14.0.7173.5000)
No auth needed
Prerequisites: Microsoft Office 2010 on Windows 7 x86 · Application Verifier enabled for reliability
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026