Teams
by Microsoft
CVEs (33)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4863 | Hig | 0.70 | 8.8 | 1.00 | KEV | Sep 12, 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | |
| CVE-2026-65667 | Cri | 0.65 | 10.0 | 0.00 | Aug 7, 2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2018-8529 | Cri | 0.65 | 9.8 | 0.13 | Nov 15, 2018 | A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team. | ||
| CVE-2026-62896 | Cri | 0.62 | 9.6 | 0.00 | Aug 7, 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-33823 | Cri | 0.62 | 9.6 | 0.01 | May 7, 2026 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-65768 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65767 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2023-29330 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2023 | Microsoft Teams Remote Code Execution Vulnerability | ||
| CVE-2023-29328 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2023 | Microsoft Teams Remote Code Execution Vulnerability | ||
| CVE-2026-42835 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-21535 | Hig | 0.53 | 8.2 | 0.01 | Feb 19, 2026 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2020-17091 | Hig | 0.51 | 7.8 | 0.02 | Nov 11, 2020 | Microsoft Teams Remote Code Execution Vulnerability | ||
| CVE-2019-5922 | Hig | 0.51 | 7.8 | 0.05 | Mar 12, 2019 | Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2026-62918 | Hig | 0.49 | 7.5 | 0.00 | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-53783 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | ||
| CVE-2022-21965 | Hig | 0.49 | 7.5 | 0.03 | Feb 9, 2022 | Microsoft Teams Denial of Service Vulnerability | ||
| CVE-2026-26133 | Hig | 0.46 | 7.1 | 0.00 | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-49737 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-42004 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program… | ||
| CVE-2024-41145 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a… |
- risk 0.70cvss 8.8epss 1.00
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.65cvss 10.0epss 0.00
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 9.8epss 0.13
A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.
- risk 0.62cvss 9.6epss 0.00
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
- risk 0.57cvss 8.8epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.02
Microsoft Teams Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Teams Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- risk 0.53cvss 8.2epss 0.01
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
- risk 0.51cvss 7.8epss 0.02
Microsoft Teams Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.05
Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.49cvss 7.5epss 0.00
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.03
Microsoft Teams Denial of Service Vulnerability
- risk 0.46cvss 7.1epss 0.00
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program…
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a…
Page 1 of 2