cbcvebase.

Microsoft Teams For Android vulnerabilities

10 known vulnerabilities affecting microsoft/microsoft_teams_for_android.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-29330P3HIGHCVSS 8.8≥ 1.0.0, < 1.0.0.20230702042023-08-08
CVE-2023-29330 [HIGH] CWE-416 CVE-2023-29330: Microsoft Teams Remote Code Execution Vulnerability Microsoft Teams Remote Code Execution Vulnerability
nvd
CVE-2023-29328P3HIGHCVSS 8.8≥ 1.0.0, < 1.0.0.20230702042023-08-08
CVE-2023-29328 [HIGH] CWE-416 CVE-2023-29328: Microsoft Teams Remote Code Execution Vulnerability Microsoft Teams Remote Code Execution Vulnerability
nvd
CVE-2026-42835P3HIGHCVSS 8.1≥ 1.0.0, < 1.0.76.20261113022026-06-09
CVE-2026-42835 [HIGH] CWE-74 CVE-2026-42835: Improper neutralization of special elements in output used by a downstream component ('injection') i Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-53783P3HIGHCVSS 7.5≥ 1.0.0, < 1416/1.0.0.20251028022025-08-12
CVE-2025-53783 [HIGH] CWE-122 CVE-2025-53783: Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-26133P3HIGHCVSS 7.1≥ 1.0.0, < 1.0.0.20260431022026-03-16
CVE-2026-26133 [HIGH] CWE-77 CVE-2026-26133: AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-32185P4MEDIUMCVSS 5.5≥ 1.0.0, < 1.0.0.20260924022026-05-12
CVE-2026-32185 [MEDIUM] CWE-552 CVE-2026-32185: Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attack Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2024-21448P4MEDIUMCVSS 5.0≥ 1.0.0, < 1.0.0.20240223022024-03-12
CVE-2024-21448 [MEDIUM] CWE-20 CVE-2024-21448: Microsoft Teams for Android Information Disclosure Vulnerability Microsoft Teams for Android Information Disclosure Vulnerability
nvd
CVE-2024-21374P4MEDIUMCVSS 5.0≥ 1.0.0, < 1.0.0.20240223022024-02-13
CVE-2024-21374 [MEDIUM] CWE-20 CVE-2024-21374: Microsoft Teams for Android Information Disclosure Vulnerability Microsoft Teams for Android Information Disclosure Vulnerability
nvd
CVE-2025-49731P4LOWCVSS 3.1≥ 1.0.0, < 1.0.0.20251129022025-07-08
CVE-2025-49731 [LOW] CWE-280 CVE-2025-49731: Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-21965HIGHCVSS 7.5≥ 1.0.0, < 1416/1.0.0.20210407012022-02-09
CVE-2022-21965 [HIGH] Microsoft Teams Denial of Service Vulnerability Microsoft Teams Denial of Service Vulnerability Microsoft Teams Denial of Service Vulnerability
cvelistv5