Executive brief
A security vulnerability in Microsoft Teams could allow an unauthorized person with local access to the computer to perform spoofing attacks. This occurs because certain files or directories are improperly accessible to external parties. An attacker could potentially use this to misrepresent information or gain unauthorized access to sensitive data within the application.
Technical details
A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in Microsoft Teams. The flaw allows an unauthorized attacker to perform spoofing locally due to improper access controls on specific application files or directories. Exploitation requires local access to the target machine and typically involves user interaction. According to the CVSS vector, the primary impact is on confidentiality (High), while integrity and availability are not directly impacted by the primary flaw, though the vendor classifies the outcome as spoofing. Microsoft has released information regarding this vulnerability in their Security Update Guide.
Affected products
- Microsoft Teams
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft
- 2026-05-12: advisory: NVD entry created