M-Files Server
cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*
- < 25.1.14445.5
- < 24.8 LTS SR3 (24.8.13981.14)
A denial-of-service vulnerability has been identified in M-Files Server versions prior to 25.1.14445.5 and before 24.8 LTS SR3. This issue arises from an unexpected server crash in the database driver, which can be triggered by a highly privileged attacker through configuration changes. The vulnerability requires a vault admin level user to add or modify External Object Types.
Exploitation of this vulnerability leads to an unexpected server crash, causing a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.