First published: Thu Jan 23 2025(Updated: )
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files | <25.1.14445.5 | |
M-Files | <24.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0648 is classified as a critical vulnerability due to its potential to cause denial of service.
To fix CVE-2025-0648, upgrade to M-Files Server version 25.1.14445.5 or later.
CVE-2025-0648 affects M-Files Server versions prior to 25.1.14445.5.
CVE-2025-0648 is a denial of service vulnerability caused by an unexpected server crash in the database driver.
CVE-2025-0648 can be exploited by a highly privileged attacker making unauthorized configuration changes.