M-Files Server Vulnerability Security Update Advisory (CVE-2024-0563)

Overview

 

An update has been made available to fix vulnerabilities in M-Files Server. Users of affected versions are advised to update to the latest version.

 

Affected Products

 

M-Files Server versions earlier than 24.2 (excluding 23.2 SR7 and 23.8 SR5)

 

Resolved Vulnerabilities

 

Denial of Service Vulnerability in M-Files Server (CVE-2024-0563)

 

Vulnerability Patches

 

Vulnerability patches were made available in the February 23, 2024 update. Please update to the latest vulnerability patch version according to the reference site.

  • M-Files Server versions 23.2 SR7, 23.8 SR5, and 24.2

 

Referenced Sites

 

[1] CVE-2024-0563 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-0563
[2] Denial of service condition in M-Files Server in versions…
https://github.com/advisories/GHSA-384m-rpvv-4rw6
[3] https://www.m-files.com/about/trust-center/security-advisories/CVE-2024-0563 
[4] m-files server up to 23.2 sr6/23.8 sr4 on windows resource consumption
https://vuldb.com/?id.254620