Impact
Microsoft Teams for Android may insert sensitive information into outgoing data packets. This flaw allows an authorized attacker who can trigger data transmission to capture and read confidential content. The vulnerability relies on improper handling of data before network transport and is categorized as CWE-201, a weakness that exposes sensitive information.
Affected Systems
The flaw affects Microsoft Teams for Android deployments. Users running any instance of the Microsoft Teams Android app are potentially exposed; no specific sub‑version list is provided, so all versions remain at risk until updated.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity risk. While the EPSS score is not available, the lack of a KEV listing suggests limited known exploitation. The attack likely requires the victim to be using Teams and to engage in normal data transmission, making exploitation possible within typical user activity but not requiring advanced privileges.
OpenCVE Enrichment