CVE-2025-49731

CWE-2804 documents4 sources
Severity
3.1LOW
EPSS
0.1%
top 71.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8

Description

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages4 packages

NVDmicrosoft/teams< 1.0.0.2025112902+1
CVEListV5microsoft/microsoft_teams_for_ios2.0.07.10.1 (100772025102901)
CVEListV5microsoft/microsoft_teams_for_android1.0.01.0.0.2025112902
CVEListV5microsoft/microsoft_teams_for_desktop1.0.025060212643

🔴Vulnerability Details

2
GHSA
GHSA-3x7p-3vvq-9qr7: Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network2025-07-08
CVEList
Microsoft Teams Elevation of Privilege Vulnerability2025-07-08

📋Vendor Advisories

1
Microsoft
Microsoft Teams Elevation of Privilege Vulnerability2025-07-08
CVE-2025-49731 (LOW CVSS 3.1) | Improper handling of insufficient p | cvebase.io