First published: Thu Apr 20 2023(Updated: )
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <23.4.12455.0 |
Update to the patched version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2112 is a vulnerability in M-Files that allows lateral movement between sessions in the desktop component service.
CVE-2023-2112 has a severity score of 7.8, which is classified as high.
CVE-2023-2112 affects M-Files versions before 23.4.12455.0, allowing lateral movement between sessions in the desktop component service.
To fix CVE-2023-2112, update M-Files to version 23.4.12455.0 or newer.
You can find more information about CVE-2023-2112 at the following link: [M-Files Security Advisories](https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2112/)