First published: Mon Apr 28 2025(Updated: )
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.
Credit: disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
GFI MailEssentials | <21.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-34491 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2025-34491, upgrade GFI MailEssentials to version 21.8 or later.
CVE-2025-34491 affects users of GFI MailEssentials prior to version 21.8.
CVE-2025-34491 can be exploited by an authenticated remote attacker using crafted serialized .NET data.
CVE-2025-34491 falls under the category of .NET deserialization vulnerabilities.