PT-2025-18105 · Gfi · Gfi Mailessentials
Frycos
·
Published
1999-01-01
·
Updated
2025-05-10
·
CVE-2025-34489
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GFI MailEssentials versions prior to 21.8
Description
A local privilege escalation issue exists, allowing a local attacker to escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service.
Recommendations
For GFI MailEssentials versions prior to 21.8, update to version 21.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the .NET Remoting Service to minimize the risk of exploitation.
Exploit
Fix
LPE
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gfi Mailessentials