Unsafe DLL Loading Vulnerability in MailEnable by MailEnable
CVE-2025-34423
8.5HIGH
What is CVE-2025-34423?
MailEnable versions prior to 10.54 are susceptible to an unsafe DLL loading vulnerability, allowing local arbitrary code execution. The vulnerability arises when the MailEnable administrative executable attempts to load MEAIAU.DLL from its installation directory without implementing proper integrity validation or a secure search order. This flaw permits a local attacker, who possesses write access to that directory, to introduce a malicious MEAIAU.DLL file. Upon execution, the malicious code runs with the system's process privileges, potentially compromising the integrity of the system and its data.
Affected Version(s)
MailEnable 0 < 10.54
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
MushroomSecTeam (Spotify, AmirSUN, M30Brad, Hannah Green, av01t3x, PG)
