CVE-2023-29328 is a Remote Code Execution vulnerability affecting Microsoft Teams. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability, requiring user interaction for exploitation. While not currently listed in CISA's KEV catalog, its high EPSS score and community discussion indicate a notable level of concern. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, but it has received media coverage in prominent cybersecurity publications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.2023070204CPE matchmatch criteria | cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:* | ||
< 1.6.00.17554CPE matchmatch criteria | cpe:2.3:a:microsoft:teams:*:*:*:*:*:macos:*:* | ||
< 1.6.00.18681CPE matchmatch criteria | cpe:2.3:a:microsoft:teams:*:*:*:*:*:-:*:* | ||
< 5.12.1CPE matchmatch criteria | cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.