CVE-2025-53783
published 2025-08-12CVE-2025-53783: Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
PriorityP346high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.78%
52.3th percentile
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365_guides | < 907.2505.29001.0 | 907.2505.29001.0 |
| microsoft | dynamics_365_remote_assist | < 316.2505.28001 | 316.2505.28001 |
| microsoft | microsoft_teams_for_android | >= 1.0.0 < 1416/1.0.0.2025102802 | 1416/1.0.0.2025102802 |
| microsoft | microsoft_teams_for_desktop | >= 1.0.0 < 25122.1415.3698.6812 | 25122.1415.3698.6812 |
| microsoft | microsoft_teams_for_ios | >= 2.0.0 < 7.10.1 (100772025102901) | 7.10.1 (100772025102901) |
| microsoft | teams | < 1.0.0.2025102802 | 1.0.0.2025102802 |
| microsoft | teams | < 7.10.1 | 7.10.1 |
| microsoft | teams | < 25122.1207.3700.1444 | 25122.1207.3700.1444 |
| microsoft | teams | < 25122.1415.3698.6812 | 25122.1415.3698.6812 |
| microsoft | teams_for_d365_guides_hololens | >= 907.0000 < 907.2505.29001.0 | 907.2505.29001.0 |
| microsoft | teams_for_d365_remote_assist_hololens | >= 316.0000 < 316.2505.28001 | 316.2505.28001 |
| microsoft | teams_panel | >= 1.0.97 < 1449/1.0.97.2025102203 | 1449/1.0.97.2025102203 |
| microsoft | teams_panels | < 1.0.97.2025102203 | 1.0.97.2025102203 |
| microsoft | teams_phone | >= 1.0.94 < 1449/1.0.94.2025168802 | 1449/1.0.94.2025168802 |
| microsoft | teams_phones | < 1.0.94.2025168802 | 1.0.94.2025168802 |
| msrc | microsoft_teams_for_android | — | — |
| msrc | microsoft_teams_for_desktop | — | — |
| msrc | microsoft_teams_for_ios | — | — |
| msrc | microsoft_teams_for_mac_new_edition | — | — |
| msrc | teams_for_d365_guides_hololens | — | — |
| msrc | teams_for_d365_remote_assist_hololens | — | — |
| msrc | teams_panels | — | — |
| msrc | teams_phones | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-56v2-hh65-7486: Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network
ghsa_unreviewed·2025-08-12
CVE-2025-53783 [HIGH] CWE-122 GHSA-56v2-hh65-7486: Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
Microsoft
Microsoft Teams Remote Code Execution Vulnerability
vendor_msrc·2025-08-12·CVSS 7.5
CVE-2025-53783 [HIGH] CWE-122 Microsoft Teams Remote Code Execution Vulnerability
Microsoft Teams Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), integrity (I:H), and availability (A:H). What does that mean for this vulnerability?
An attacker who successfully exploited this vulnerability could gain high privileges, which include read, write, and delete functionality.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
Mic
No detection rules found.
No public exploits indexed.
2025-08-12
Published