Microsoft
Microsoft Teams: vulnerabilidades y CVE
Microsoft Teams tiene 32 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses14
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-4863 | Alta (8.8) | 100% | ⚠ Explotación activa | 12 sept 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69559 | Media (6.3) | 0.32% | — | 8 sept 2026 | Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. |
| CVE-2026-65812 | Media (6.8) | 0.89% | — | 8 sept 2026 | Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. |
| CVE-2026-65769 | Alta (7.5) | 0.92% | — | 11 ago 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-65768 | Crítica (9.8) | 0.94% | — | 11 ago 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. |
| CVE-2026-65767 | Alta (7.6) | 0.61% | — | 11 ago 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-65667 | Crítica (10) | 0.80% | — | 7 ago 2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-62918 | Alta (7.5) | 0.50% | — | 7 ago 2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-62896 | Crítica (9.6) | 0.69% | — | 7 ago 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42835 | Alta (8.1) | 1.2% | — | 9 jun 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. |
| CVE-2026-49139 | Alta (7) | 0.66% | — | 1 jun 2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged… |
| CVE-2026-32185 | Media (5.5) | 0.55% | — | 12 may 2026 | Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-33823 | Media (6.5) | 0.86% | — | 7 may 2026 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. |
| CVE-2026-26133 | Alta (7.1) | 0.54% | — | 16 mar 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-21535 | Alta (7.5) | 0.60% | — | 19 feb 2026 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-53783 | Alta (7.5) | 0.81% | — | 12 ago 2025 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49737 | Alta (7) | 0.19% | — | 8 jul 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49731 | Baja (3.1) | 0.43% | — | 8 jul 2025 | Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-42004 | Crítica (9.8) | 0.81% | — | 18 dic 2024 | A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A… |
| CVE-2024-41145 | Crítica (9.8) | 0.80% | — | 18 dic 2024 | A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a… |
| CVE-2024-41138 | Crítica (9.8) | 0.91% | — | 18 dic 2024 | A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access… |
| CVE-2024-38197 | Media (6.5) | 16% | — | 13 ago 2024 | Microsoft Teams for iOS Spoofing Vulnerability |
| CVE-2024-21448 | Media (5) | 1.2% | — | 12 mar 2024 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2024-21374 | Media (5) | 0.97% | — | 13 feb 2024 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2023-4863 | Alta (8.8) | 100% | ⚠ Explotación activa | 12 sept 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
| CVE-2023-29330 | Alta (8.8) | 2.0% | — | 8 ago 2023 | Microsoft Teams Remote Code Execution Vulnerability |
| CVE-2023-29328 | Alta (8.8) | 2.2% | — | 8 ago 2023 | Microsoft Teams Remote Code Execution Vulnerability |
| CVE-2023-24881 | Media (6.5) | 1.5% | — | 11 jul 2023 | Microsoft Teams Information Disclosure Vulnerability |
| CVE-2022-21965 | Alta (7.5) | 3.0% | — | 9 feb 2022 | Microsoft Teams Denial of Service Vulnerability |
| CVE-2021-24114 | Media (5.7) | 3.2% | — | 25 feb 2021 | Microsoft Teams iOS Information Disclosure Vulnerability |
| CVE-2020-10146 | Media (5.4) | 2.3% | — | 9 dic 2020 | The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.