Unsafe DLL Loading Vulnerability in MailEnable by MailEnable
CVE-2025-34423

8.5HIGH

Key Information:

Vendor

Mailenable

Vendor
CVE Published:
10 December 2025

What is CVE-2025-34423?

MailEnable versions prior to 10.54 are susceptible to an unsafe DLL loading vulnerability, allowing local arbitrary code execution. The vulnerability arises when the MailEnable administrative executable attempts to load MEAIAU.DLL from its installation directory without implementing proper integrity validation or a secure search order. This flaw permits a local attacker, who possesses write access to that directory, to introduce a malicious MEAIAU.DLL file. Upon execution, the malicious code runs with the system's process privileges, potentially compromising the integrity of the system and its data.

Affected Version(s)

MailEnable 0 < 10.54

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MushroomSecTeam (Spotify, AmirSUN, M30Brad, Hannah Green, av01t3x, PG)
.
CVE-2025-34423 : Unsafe DLL Loading Vulnerability in MailEnable by MailEnable