CVE-2025-49737: Microsoft Teams

High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft Teams: before 25163.3001.3726.6503 (fixed in 25163.3001.3726.6503)

Published 2025-07-08. Last modified 2026-06-17.