๐Ÿ” CVE Alert

CVE-2025-34396

UNKNOWN 0.0

MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAINFY.DLL

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAINFY.DLL from its application directo without sufficient integrity validation or secure search order. If the DLL is missing or attacker-writable locations in the search path are used, a local attacker with write permissions to the directory can plant a malicious MEAINFY.DLL. When the executable is launched, it loads the attacker-controlled library and executes code with the privileges of the process, enabling local privilege escalation when run with elevated rights.

CWE CWE-427
Vendor mailenable
Product mailenable
Published Dec 9, 2025
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for mailenable mailenable

Be the first to know when new unknown vulnerabilities affecting mailenable mailenable are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MailEnable / MailEnable
0 < 10.54

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mailenable.com: https://mailenable.com/Standard-ReleaseNotes.txt mailenable.com: https://www.mailenable.com/ vulncheck.com: https://www.vulncheck.com/advisories/mailenable-dll-hijacking-via-unsafe-loading-of-meainfy-dll

Credits

MushroomSecTeam (Spotify, AmirSUN, M30Brad, Hannah Green, av01t3x, PG)