« Volver al listado

Microsoft

Microsoft Teams: vulnerabilidades y CVE

Microsoft Teams tiene 32 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE32
Últimos 12 meses14
Críticas6
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69559Media (6.3)0.32%—8 sept 2026
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-65812Media (6.8)0.89%—8 sept 2026
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-65769Alta (7.5)0.92%—11 ago 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-65768Crítica (9.8)0.94%—11 ago 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
CVE-2026-65767Alta (7.6)0.61%—11 ago 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
CVE-2026-65667Crítica (10)0.80%—7 ago 2026
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62918Alta (7.5)0.50%—7 ago 2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62896Crítica (9.6)0.69%—7 ago 2026
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-42835Alta (8.1)1.2%—9 jun 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-49139Alta (7)0.66%—1 jun 2026
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged…
CVE-2026-32185Media (5.5)0.55%—12 may 2026
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-33823Media (6.5)0.86%—7 may 2026
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-26133Alta (7.1)0.54%—16 mar 2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-21535Alta (7.5)0.60%—19 feb 2026
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CVE-2025-53783Alta (7.5)0.81%—12 ago 2025
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
CVE-2025-49737Alta (7)0.19%—8 jul 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
CVE-2025-49731Baja (3.1)0.43%—8 jul 2025
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2024-42004Crítica (9.8)0.81%—18 dic 2024
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A…
CVE-2024-41145Crítica (9.8)0.80%—18 dic 2024
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a…
CVE-2024-41138Crítica (9.8)0.91%—18 dic 2024
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access…
CVE-2024-38197Media (6.5)16%—13 ago 2024
Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-21448Media (5)1.2%—12 mar 2024
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2024-21374Media (5)0.97%—13 feb 2024
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…
CVE-2023-29330Alta (8.8)2.0%—8 ago 2023
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-29328Alta (8.8)2.2%—8 ago 2023
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-24881Media (6.5)1.5%—11 jul 2023
Microsoft Teams Information Disclosure Vulnerability
CVE-2022-21965Alta (7.5)3.0%—9 feb 2022
Microsoft Teams Denial of Service Vulnerability
CVE-2021-24114Media (5.7)3.2%—25 feb 2021
Microsoft Teams iOS Information Disclosure Vulnerability
CVE-2020-10146Media (5.4)2.3%—9 dic 2020
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1005 Data from Local System3
  3. T1059 Command and Scripting Interpreter3
  4. T1203 Exploitation for Client Execution3
  5. T1078 Valid Accounts2
  6. T1210 Exploitation of Remote Services2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft