Teams and Photos updates contain Security Vulnerabilities.

AJ Edward 0 Reputation points
2025-07-09T12:23:37.04+00:00

MS Teams, msix version contains sqllite.dll version 3.49.0 which is flagged by Nessus (plugin ID 240237)

This is also the case with Windows.Photos

Microsoft Teams | Microsoft Teams for business | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Teddie-D 3,920 Reputation points Microsoft External Staff Moderator
    2025-07-10T00:33:19.82+00:00

    Hi @AJ Edward
    Thank you for posting your question in the Microsoft Q&A forum. 

    I’m truly sorry for the inconvenience this issue has caused and understand how frustrating it can be when trusted applications are flagged during security scans. 

    To mitigate this, the recommended action is to upgrade to SQLite version 3.49.1 or later, which addresses the vulnerability. However, since MS Teams and Windows.Photos are packaged and maintained by Microsoft, direct updates to embedded components like sqlite.dll may not be feasible manually. 
    You can refer to SQLite 3.44.0 < 3.49.1 Multiple Vulnerabilities | Tenable® 
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link. 
    Please keep an eye on Version update history for Teams app deployments - Office release notes | Microsoft Learn to track Microsoft’s release notes and security bulletins for updates to Teams and Windows.Photos that may include patched versions of sqlite.dll. 
    If possible, please consider isolating affected apps using application control or sandboxing to reduce risk while awaiting an official fix.  
    Thank you for your patience and understanding.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.