Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
History

Thu, 20 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:*
cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Mon, 17 Nov 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared M-files
M-files m-files Server
M-files server
Vendors & Products M-files
M-files m-files Server
M-files server

Mon, 17 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Nov 2025 13:30:00 +0000

Type Values Removed Values Added
Description Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an authenticated user to cause the MFserver process to crash. Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.

Mon, 17 Nov 2025 11:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an authenticated user to cause the MFserver process to crash.
Title Denial of Service condition in M-Files Server
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published: 2025-11-17T11:30:25.324Z

Updated: 2025-11-17T14:36:42.885Z

Reserved: 2025-10-13T10:29:59.870Z

Link: CVE-2025-11681

cve-icon Vulnrichment

Updated: 2025-11-17T14:35:38.416Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-17T12:15:43.250

Modified: 2025-11-20T20:35:07.147

Link: CVE-2025-11681

cve-icon Redhat

No data.