Unsafe DLL Loading Vulnerability in MailEnable Software by MailEnable
CVE-2025-34419

8.5HIGH

Key Information:

Vendor

Mailenable

Vendor
CVE Published:
10 December 2025

What is CVE-2025-34419?

MailEnable, a widely used email server software, is susceptible to an unsafe DLL loading vulnerability in versions preceding 10.54. This flaw arises when the MailEnable administrative executable attempts to load the MEAISM.DLL file from its installation directory without implementing adequate integrity checks or a secure search order. Consequently, a malicious actor with write access to this directory can plant a compromised MEAISM.DLL file, which will be executed under the context and privileges of the initiating process when the executable starts. This could potentially lead to local arbitrary code execution, enabling unauthorized access and control over the affected system.

Affected Version(s)

MailEnable 0 < 10.54

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MushroomSecTeam (Spotify, AmirSUN, M30Brad, Hannah Green, av01t3x, PG)
.
CVE-2025-34419 : Unsafe DLL Loading Vulnerability in MailEnable Software by MailEnable