Impact
An improper authorization flaw enables an attacker who already has legitimate access to Microsoft Teams to read sensitive data that should be protected. The vulnerability allows the disclosure of information over the network, compromising confidentiality and potentially exposing internal communications or event details.
Affected Systems
The vulnerability affects Microsoft Teams. No specific versions or patches are listed in the data, so all current deployments of Teams are considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.6 classifies this issue as critical, indicating a high likelihood of successful exploitation and severe impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The description that the attacker must be authorized and can retrieve data over a network implies that the attack vector is remote network traffic. This inference is drawn from the statement that the flaw allows an authorized attacker to disclose information over a network.
OpenCVE Enrichment