CVE-2025-34421: MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLL
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISP.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with write access to that directory can plant a malicious MEAISP.DLL, which is then loaded on execution, resulting in attacker-controlled code running with the privileges of the process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34421?
CVE-2025-34421 has a high severity rating due to its potential for local arbitrary code execution.
How do I fix CVE-2025-34421?
To fix CVE-2025-34421, update MailEnable to version 10.54 or later to ensure safe DLL loading.
What types of systems are affected by CVE-2025-34421?
CVE-2025-34421 affects all versions of MailEnable prior to 10.54.
What can happen if CVE-2025-34421 is exploited?
Exploitation of CVE-2025-34421 can allow an attacker to execute arbitrary code on the affected system.
Who is responsible for addressing CVE-2025-34421?
The responsibility for addressing CVE-2025-34421 falls on the users of MailEnable, who must ensure they have the latest version installed.