CVE-2023-0213: Local Elevation of Privilege in M-Files
Published Mar 29, 2023
·Updated
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
Affected Software
4 affected components
All of the following
M-Files M-Files<22.6
Microsoft Windows
M-Files M-Files<22.6
Microsoft Windows
Remediation
Information
Update to version 22.6 or newer.
Event History
Mar 29, 2023
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the Elevation of privilege issue in M-Files Installer?
The vulnerability ID is CVE-2023-0213.
2
What is the severity rating of CVE-2023-0213?
CVE-2023-0213 has a severity rating of 7.8, which is considered high.
3
What is the affected software by CVE-2023-0213?
The affected software by CVE-2023-0213 is M-Files Installer versions before 22.6 on Windows.
4
How does CVE-2023-0213 allow gaining SYSTEM privileges?
CVE-2023-0213 allows gaining SYSTEM privileges through DLL hijacking.
5
Where can I find more information about CVE-2023-0213?
You can find more information about CVE-2023-0213 in the M-Files Trust Center Security Advisories: [link](https://www.m-files.com/about/trust-center/security-advisories/cve-2023-0213/)