Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft teams Microsoft teams For Mac |
|
| Vendors & Products |
Microsoft
Microsoft teams Microsoft teams For Mac |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. | |
| Title | Microsoft Teams Elevation of Privilege Vulnerability | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published: 2025-07-08T16:58:14.537Z
Updated: 2025-08-23T00:40:35.866Z
Reserved: 2025-06-09T22:49:37.617Z
Link: CVE-2025-49737
Updated: 2025-07-11T13:24:22.041Z
Status : Awaiting Analysis
Published: 2025-07-08T17:16:02.460
Modified: 2025-07-10T13:18:53.830
Link: CVE-2025-49737
No data.