CVE-2025-11681: Denial of Service condition in M-Files Server
Published Nov 17, 2025
·Updated
Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
Affected Software
4 affected components
M-Files M-Files server<25.11.15392.1, <25.2 LTS SR2, <25.8 LTS SR2
M-Files M-Files server<25.2.14524.13
M-Files M-Files server<25.11.15392.1
M-Files M-Files server>=25.8.15085.13<25.8.15085.17
Event History
Nov 17, 2025
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11681?
CVE-2025-11681 has a high severity level due to its potential to cause denial-of-service.
2
How do I fix CVE-2025-11681?
To fix CVE-2025-11681, upgrade to M-Files Server version 25.11.15392.1 or later.
3
Who is affected by CVE-2025-11681?
CVE-2025-11681 affects authenticated users of M-Files Server versions prior to 25.11.15392.1.
4
What type of vulnerability is CVE-2025-11681?
CVE-2025-11681 is categorized as a denial-of-service vulnerability.
5
Can CVE-2025-11681 be exploited remotely?
CVE-2025-11681 requires authenticated access, meaning it cannot be exploited remotely without credentials.