CVE-2012-4914

CoolPDF 3.0.2.256 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2012-4914. PoCs published by Metasploit, Chris Gabriel, Francis Provencher, Chris Gabriel, juan vazquez, including Metasploit module exploits/windows/fileformat/coolpdf_image_stream_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Cool PDF Reader prior to version 3.0.2.256 by crafting a malformed PDF file with a specially crafted image stream. It achieves remote code execution by leveraging a SEH overwrite technique.

Description

Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a PDF document with a crafted stream.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/24876

This Metasploit module exploits a stack buffer overflow in Cool PDF Reader prior to version 3.0.2.256 by crafting a malformed PDF file with a specially crafted image stream. It achieves remote code execution by leveraging a SEH overwrite technique.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cool PDF Reader < 3.0.2.256
No auth needed
Prerequisites: Victim must open the malformed PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Chris Gabriel · textdoswindows
https://www.exploit-db.com/exploits/24463

This exploit targets a buffer overflow vulnerability in Cool PDF Reader 3.0.2.256, allowing arbitrary code execution via a crafted file. The PoC is designed to trigger the overflow and execute shellcode.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cool PDF Reader 3.0.2.256
No auth needed
Prerequisites: Victim must open a maliciously crafted file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Francis Provencher, Chris Gabriel, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/coolpdf_image_stream_bof.rb

This Metasploit module exploits a stack buffer overflow in Cool PDF Reader by crafting a malformed PDF with a specially crafted image stream. It targets Cool PDF versions prior to 3.0.2.256 and delivers a payload via a structured PDF file.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cool PDF Reader < 3.0.2.256
No auth needed
Prerequisites: Victim must open the malformed PDF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51602

Scores

EPSS 0.2839
EPSS Percentile 97.9%

Details

CWE
CWE-119
Status published
Products (1)
coolpdf/coolpdf 3.0.2.256
Published Jan 26, 2013
Tracked Since Feb 18, 2026