Teams Admin Center Log Exposes Sensitive Data During Config Changes
CVE-2025-14432 Published on December 16, 2025

Poly Video - Sensitive Data Might Be Written to Log File
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.

NVD

Weakness Type

Insertion of Sensitive Information into Log File

Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.


Products Associated with CVE-2025-14432

Want to know whenever a new CVE is published for Microsoft Teams? stack.watch will email you.

 

Affected Versions

HP Inc Poly G7500: HP Inc Poly Studio G62: HP Inc Poly Studio X72: HP Inc Poly Studio X52: HP Inc Poly Studio X32: HP Inc Poly Studio X70: HP Inc Poly Studio X50: HP Inc Poly Studio X30: HP Inc Poly Studio E70: HP Inc Poly Studio E60: HP Inc Poly EagleEye Cube: HP Inc Polycom EagleEye IV: HP Inc Poly Studio A2: HP Inc Poly Studio USB: HP Inc TC8: HP Inc TC10:

Exploit Probability

EPSS
0.04%
Percentile
11.29%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.