CVE-2025-0648: M-Files Server crash via EOT database driver configuration
Published Jan 23, 2025
·Updated
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.
Affected Software
4 affected components
M-Files M-Files server<25.1.14445.5
M-Files M-Files server<24.8
M-Files M-Files server<24.8.13981.14
M-Files M-Files server>=24.9.14055.3<25.1.14445.5
Event History
Jan 23, 2025
CVE Published
via MITRE·11:06 AM
Data Sourced
via MITRE·11:06 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0648?
CVE-2025-0648 is classified as a critical vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2025-0648?
To fix CVE-2025-0648, upgrade to M-Files Server version 25.1.14445.5 or later.
3
Who is affected by CVE-2025-0648?
CVE-2025-0648 affects M-Files Server versions prior to 25.1.14445.5.
4
What type of vulnerability is CVE-2025-0648?
CVE-2025-0648 is a denial of service vulnerability caused by an unexpected server crash in the database driver.
5
What conditions lead to the exploitation of CVE-2025-0648?
CVE-2025-0648 can be exploited by a highly privileged attacker making unauthorized configuration changes.