« Volver al listado

Microsoft

Microsoft Teams: vulnerabilidades y CVE

Microsoft Teams tiene 32 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE32
Últimos 12 meses14
Críticas6
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69559Media (6.3)0.32%—8 sept 2026
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-65812Media (6.8)0.89%—8 sept 2026
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-65769Alta (7.5)0.92%—11 ago 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-65768Crítica (9.8)0.94%—11 ago 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
CVE-2026-65767Alta (7.6)0.61%—11 ago 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
CVE-2026-65667Crítica (10)0.80%—7 ago 2026
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62918Alta (7.5)0.50%—7 ago 2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62896Crítica (9.6)0.69%—7 ago 2026
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2026-42835Alta (8.1)1.2%—9 jun 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-49139Alta (7)0.66%—1 jun 2026
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged…
CVE-2026-32185Media (5.5)0.55%—12 may 2026
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-33823Media (6.5)0.86%—7 may 2026
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-26133Alta (7.1)0.54%—16 mar 2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-21535Alta (7.5)0.60%—19 feb 2026
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CVE-2025-53783Alta (7.5)0.81%—12 ago 2025
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
CVE-2025-49737Alta (7)0.19%—8 jul 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
CVE-2025-49731Baja (3.1)0.43%—8 jul 2025
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2024-42004Crítica (9.8)0.81%—18 dic 2024
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A…
CVE-2024-41145Crítica (9.8)0.80%—18 dic 2024
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a…
CVE-2024-41138Crítica (9.8)0.91%—18 dic 2024
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access…
CVE-2024-38197Media (6.5)16%—13 ago 2024
Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-21448Media (5)1.2%—12 mar 2024
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2024-21374Media (5)0.97%—13 feb 2024
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…
CVE-2023-29330Alta (8.8)2.0%—8 ago 2023
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-29328Alta (8.8)2.2%—8 ago 2023
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-24881Media (6.5)1.5%—11 jul 2023
Microsoft Teams Information Disclosure Vulnerability
CVE-2022-21965Alta (7.5)3.0%—9 feb 2022
Microsoft Teams Denial of Service Vulnerability
CVE-2021-24114Media (5.7)3.2%—25 feb 2021
Microsoft Teams iOS Information Disclosure Vulnerability
CVE-2020-10146Media (5.4)2.3%—9 dic 2020
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1059 Command and Scripting Interpreter2
  3. T1078 Valid Accounts2
  4. T1005 Data from Local System1
  5. T1059.007 JavaScript1
  6. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft