HomeSecurityWarning! Serious vulnerabilities in Microsoft Teams

Warning! Serious vulnerabilities in Microsoft Teams

Cybersecurity researchers have revealed details of four security vulnerabilities in Microsoft Teamsthat could expose users to serious impersonation and social engineering.

Microsoft Teams vulnerabilities

These vulnerabilities “ allowed attackers to manipulate conversations, impersonate colleagues, and exploit notifications ,” Check Point said .

See also: Hackers scour the internet for RCE vulnerability exploit in XWiki

After a responsible disclosure in March 2024, some of the issues were addressed by Microsoft (in August 2024). Subsequent fixes were released in September 2024 and October 2025.

The vulnerabilities in Microsoft Teams make it possible to change the content of messages without leaving the “Edited” mark and the sender’s identity. It is also possible to modify incoming notifications to change the apparent sender of the message. This allows an attacker to trick victims into opening malicious messages by making them appear to come from a trusted source.

See also: Android: Critical 0-click vulnerability allows RCE attacks

Warning! Serious vulnerabilities in Microsoft Teams

The attack, which targets both external guest users and internal malicious actors, poses serious risks. It undermines security boundaries and allows potential targets to perform unwanted actions, such as clicking on malicious links sent in messages or sharing sensitive data.

The vulnerabilities also allowed display names in private conversations to be changed by modifying the conversation subject. In addition, it was possible to arbitrarily modify the display names used in call notifications and during the call, allowing an attacker to spoof caller IDs.

“Together, these vulnerabilities show how attackers can erode the fundamental trust that makes collaboration tools effective, turning Teams from a business enhancer into a vehicle for deception,” the cybersecurity firm said.

Microsoft Teams for iOS

Microsoft described CVE-2024-38197 (CVSS score: 6.5) as a medium severity issue affecting Teams for iOS. It could allow an attacker to change the sender name of a message in Teams and trick users into revealing sensitive information through social engineering techniques.

See also: Malicious ads for PuTTY and Teams distribute malware

Warning! Serious vulnerabilities in Microsoft Teams

The findings come as malicious actors exploit Microsoft's communications platform in a variety of ways, including approaching targets and convincing them to grant remote access or execute a malicious payload.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS