logo

Exploiting Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed

ID: 51fb28dc-d1b9-501e-b86b-eb1b040a5945

STIX ID: report--51fb28dc-d1b9-501e-b86b-eb1b040a5945

Feed Name: Check Point Research

Threat Score
70/100

Date Published: 2025-11-04

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Executive summary:** Check Point Research discovered four critical manipulation and spoofing vulnerabilities in Microsoft Teams allowing guest or insider attackers to convincingly impersonate users, edit messages without an "Edited" label, spoof notification sender names (CVE-2024-38197), alter private chat display names via conversation topics, and forge caller identities in calls; Microsoft was notified in March 2024 and issued fixes through October 2025, but the issues illustrate severe risks to trust, phishing, financial fraud, and information integrity across the platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.