Impact
Microsoft Teams does not properly verify the cryptographic signature on messages or calls, allowing an attacker who can send data over the network to impersonate legitimate participants. The lack of signature validation means the attacker could inject deceptive content or initiate calls that appear to come from trusted users, potentially enabling phishing, social engineering, or other malicious interactions within Teams. This flaw does not provide direct code execution but severely undermines authentication integrity and could affect the confidentiality of private communications.
Affected Systems
The vulnerability impacts Microsoft Teams across all installations, as no specific version details are disclosed in the CNA data. The CNA lists Microsoft Teams as the affected product, and the CPE entry indicates all versions are potentially affected until a patch is applied. System administrators should verify that their Teams deployments are running the latest releases or have applied the fix identified in the Microsoft Security Response Center update guide.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and while an EPSS score is not available, the flaw is exploitable over a network where the attacker can send crafted packets. The vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the attack vector is most likely remote over the network; the attacker must be able to send or receive data to the Teams client. Successful exploitation would allow impersonation but does not grant additional system privileges.
OpenCVE Enrichment