CVE-2025-49731
published 2025-07-08CVE-2025-49731: Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
PriorityP414low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.37%
29.6th percentile
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_teams_for_android | >= 1.0.0 < 1.0.0.2025112902 | 1.0.0.2025112902 |
| microsoft | microsoft_teams_for_desktop | >= 1.0.0 < 25060212643 | 25060212643 |
| microsoft | microsoft_teams_for_ios | >= 2.0.0 < 7.10.1 (100772025102901) | 7.10.1 (100772025102901) |
| microsoft | teams | < 1.0.0.2025112902 | 1.0.0.2025112902 |
| microsoft | teams | < 7.10.1 | 7.10.1 |
| msrc | microsoft_teams_for_android | — | — |
| msrc | microsoft_teams_for_desktop | — | — |
| msrc | microsoft_teams_for_ios | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_msrc3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3x7p-3vvq-9qr7: Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network
ghsa_unreviewed·2025-07-08
CVE-2025-49731 [LOW] CWE-280 GHSA-3x7p-3vvq-9qr7: Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Microsoft
Microsoft Teams Elevation of Privilege Vulnerability
vendor_msrc·2025-07-08·CVSS 3.1
CVE-2025-49731 [LOW] CWE-280 Microsoft Teams Elevation of Privilege Vulnerability
Microsoft Teams Elevation of Privilege Vulnerability
Description: Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L),but lead to no
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published