Impact
The vulnerability involves an improper file path limitation in Microsoft Teams for Android, enabling an unauthorized attacker to traverse into restricted directories and execute arbitrary code. This flaw is formally categorized as CWE-22, a path traversal weakness. The potential impact is the execution of malicious code remotely, compromising device integrity, confidentiality, and availability.
Affected Systems
Microsoft Teams for Android is the affected product. No specific version details are listed in the current advisory.
Risk and Exploitability
The CVSS score is 8.8, signifying high severity, while the EPSS score is not available, so the exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this path traversal flaw over a network connection to the Teams app, allowing them to provide a crafted file name that bypasses directory restrictions and runs code on the device.
OpenCVE Enrichment