CVE-2025-34423: MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIAU.DLL
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIAU.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with write access to that directory can plant a malicious MEAIAU.DLL, which is then loaded on execution, resulting in attacker-controlled code running with the privileges of the process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34423?
CVE-2025-34423 is classified as a high severity vulnerability due to its potential for local arbitrary code execution.
How do I fix CVE-2025-34423?
To fix CVE-2025-34423, upgrade MailEnable to version 10.54 or later, which addresses the unsafe DLL loading vulnerability.
What versions of MailEnable are affected by CVE-2025-34423?
CVE-2025-34423 affects all MailEnable versions prior to 10.54.
What kind of attack can CVE-2025-34423 enable?
CVE-2025-34423 can enable an attacker to execute arbitrary code locally through unsafe DLL loading.
Is there a patch available for CVE-2025-34423?
Yes, a patch is available by upgrading to MailEnable version 10.54 or higher.