Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround available on affected versions.

History

Fri, 21 Nov 2025 05:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:*
cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Tue, 18 Nov 2025 00:30:00 +0900

Type Values Removed Values Added
First Time appeared M-files
M-files m-files Server
M-files server
Vendors & Products M-files
M-files m-files Server
M-files server

Tue, 18 Nov 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Nov 2025 22:30:00 +0900

Type Values Removed Values Added
Description Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an authenticated user to cause the MFserver process to crash. Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.

Mon, 17 Nov 2025 20:45:00 +0900

Type Values Removed Values Added
Description Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an authenticated user to cause the MFserver process to crash.
Title Denial of Service condition in M-Files Server
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2026-01-21T08:15:26.780Z

Reserved: 2025-10-13T10:29:59.870Z

Link: CVE-2025-11681

cve-icon Vulnrichment

Updated: 2025-11-17T14:35:38.416Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-17T12:15:43.250

Modified: 2025-11-20T20:35:07.147

Link: CVE-2025-11681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-18T00:15:24Z

Weaknesses