CVE-2023-2112: Desktop component allows lateral movement between sessions
Published Apr 20, 2023
·Updated
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
Affected Software
1 affected component
M-Files M-Files server<23.4.12455.0
Remediation
Information
Update to the patched version.
Event History
Apr 20, 2023
CVE Published
via MITRE·08:05 AM
Data Sourced
via MITRE·08:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-2112?
CVE-2023-2112 is a vulnerability in M-Files that allows lateral movement between sessions in the desktop component service.
2
What is the severity of CVE-2023-2112?
CVE-2023-2112 has a severity score of 7.8, which is classified as high.
3
How does CVE-2023-2112 affect M-Files?
CVE-2023-2112 affects M-Files versions before 23.4.12455.0, allowing lateral movement between sessions in the desktop component service.
4
How do I fix CVE-2023-2112?
To fix CVE-2023-2112, update M-Files to version 23.4.12455.0 or newer.
5
Where can I find more information about CVE-2023-2112?
You can find more information about CVE-2023-2112 at the following link: [M-Files Security Advisories](https://www.m-files.com/about/trust-center/security-advisories/cve-2023-2112/)