CVE-2023-2480: Elevation of Privilege in M-Files Desktop Client
Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications
Other sources
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-2480.
What is the title of this vulnerability?
The title of this vulnerability is 'Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege.'
What is the severity of CVE-2023-2480?
The severity of CVE-2023-2480 is high with a severity value of 7.8.
How does CVE-2023-2480 allow elevation of privilege?
CVE-2023-2480 allows elevation of privilege via UI extension applications.
How can I fix the CVE-2023-2480 vulnerability?
To fix the CVE-2023-2480 vulnerability, update your M-Files Client to version 23.5.12598.0 or newer, excluding 23.2 SR2 and newer.