CVE-2025-11681

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
M-Files CorporationCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
m-filesm-files_server
𝑥
< 25.2.14524.13
m-filesm-files_server
𝑥
< 25.11.15392.1
m-filesm-files_server
25.8.15085.13 ≤
𝑥
< 25.8.15085.17
𝑥
= Vulnerable software versions