CVE-2019-25572

NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the email input field. Attackers can paste a buffer of 100,000 characters into the email field during login to trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nordvpn:nordvpn:*:*:*:*:*:windows:*:*

History

15 Apr 2026, 17:12

Type Values Removed Values Added
CPE cpe:2.3:a:nordvpn:nordvpn:*:*:*:*:*:windows:*:*
Summary
  • (es) NordVPN 6.19.6 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales provocar un fallo en la aplicación al enviar una cadena excesivamente larga en el campo de entrada de correo electrónico. Los atacantes pueden pegar un búfer de 100.000 caracteres en el campo de correo electrónico durante el inicio de sesión para provocar un fallo en la aplicación.
References () https://downloads.nordcdn.com/apps/windows/10/NordVPN/latest/NordVPNSetup.exe - () https://downloads.nordcdn.com/apps/windows/10/NordVPN/latest/NordVPNSetup.exe - Broken Link
References () https://nordvpn.com/ - () https://nordvpn.com/ - Product
References () https://www.exploit-db.com/exploits/46343 - () https://www.exploit-db.com/exploits/46343 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/nordvpn-denial-of-service-via-email-field-buffer-overflow - () https://www.vulncheck.com/advisories/nordvpn-denial-of-service-via-email-field-buffer-overflow - Third Party Advisory
First Time Nordvpn nordvpn
Nordvpn

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-04-15 17:12


NVD link : CVE-2019-25572

Mitre link : CVE-2019-25572

CVE.ORG link : CVE-2019-25572


JSON object : View

Products Affected

nordvpn

  • nordvpn
CWE
CWE-1260

Improper Handling of Overlap Between Protected Memory Ranges