
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25572 is a denial of service (DoS) vulnerability in NordVPN 6.19.6 for Windows that allows local attackers to crash the application by submitting an excessively long string in the email input field during login. Specifically, pasting a buffer of approximately 100,000 characters into the email field triggers an application crash. The affected product scope is NordVPN for Windows up to and including version 6.19.6. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (Feedly, VulnCheck Advisory).
The root cause is classified under CWE-1260 (Improper Handling of Overlap Between Protected Memory Ranges), with an estimated secondary classification of CWE-125 (Out-of-bounds Read). The vulnerability arises from insufficient input length validation in the email field of the NordVPN Windows login interface, allowing an oversized input buffer to corrupt memory and crash the application. Exploitation requires local access to the machine and the ability to interact with the NordVPN login UI. A proof-of-concept exploit was published on Exploit-DB (EDB-46343) demonstrating the crash via a 100,000-character paste into the email field (Exploit-DB, VulnCheck Advisory).
Successful exploitation results in a crash of the NordVPN application, causing a loss of VPN connectivity for the affected user (availability impact). There is no known confidentiality or integrity impact — the vulnerability does not expose data or allow unauthorized modification of system state. The scope is limited to the local NordVPN client process; no lateral movement or privilege escalation has been demonstrated (Feedly, VulnCheck Advisory).
A proof-of-concept exploit is publicly available on Exploit-DB (EDB-46343), though it has been assessed as not a real weaponized exploit — it demonstrates a simple UI-based crash rather than code execution. The EPSS score is extremely low at 0.000120, indicating minimal probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and this CVE does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Exploit-DB, Feedly).
python -c "print('A' * 100000)").NordVPN.exe) without user-initiated shutdown.NordVPN.exe around the time of the incident.Users should upgrade NordVPN for Windows to a version beyond 6.19.6, as the vulnerability is fixed in later releases available via the official NordVPN download page. As a workaround, restricting local user access to the NordVPN application or deploying endpoint controls that limit clipboard paste operations in sensitive applications can reduce exposure. Organizations should monitor for unexpected NordVPN process crashes as a detection measure (VulnCheck Advisory, NordVPN).
Coverage of CVE-2019-25572 has been limited to vulnerability aggregator sites and automated CVE feeds, with no notable vendor statements, researcher commentary, or significant media coverage identified. The vulnerability was assigned by VulnCheck and published in March 2026 despite the original discovery dating to 2019 (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."