Four vulnerabilities uncovered in Microsoft Teams could have allowed attackers to manipulate messages, forge notifications, and impersonate trusted contacts, turning the collaboration platform into a powerful tool for social engineering.
Cybersecurity researchers have revealed four security flaws in Microsoft Teams that could have enabled threat actors to impersonate colleagues, alter messages, and send fake notifications to trick users into revealing sensitive information.
According to Check Point, the vulnerabilities “allowed attackers to manipulate conversations, impersonate colleagues, and exploit notifications.” In essence, the flaws made it possible to change message content without displaying the “Edited” label, alter the sender’s identity, and modify incoming notifications so they appeared to come from trusted contacts, including senior executives. This allowed attackers to send seemingly legitimate messages to colleagues, luring them into opening malicious links or disclosing confidential information.
The attack scenario could be exploited both by external guest users and internal malicious insiders, undermining the trust that underpins enterprise collaboration. Victims could easily be manipulated into taking harmful actions, from clicking infected links to sharing corporate credentials.
The vulnerabilities also extended to Teams’ chat and call interfaces. Attackers could alter display names in private messages by modifying the conversation topic, or change caller names during voice and video calls, effectively spoofing identities and creating a convincing illusion of authenticity.
“Together, these vulnerabilities show how attackers can erode the fundamental trust that makes collaboration workspace tools effective, turning Teams from a business enabler into a vector for deception,” Check Point said.
Microsoft has described CVE-2024-38197 as a medium-severity spoofing issue affecting Teams for iOS, warning that an attacker could modify the sender name in messages and trick recipients into divulging sensitive information through social engineering.
The discovery highlights the growing importance of message integrity and identity verification within corporate collaboration tools, where even minor interface flaws can be exploited for large-scale deception.
Share this article