CVE-2019-25467

HIGH

Verypdf docPrint Pro 8.0 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25467. PoCs published by Connor McGarr.

AI-analyzed exploit summary This exploit demonstrates a local SEH-based buffer overflow in docPrint Pro v8.0, leveraging alphanumeric shellcode to bypass bad character restrictions and achieve arbitrary code execution via a crafted payload in the 'User/Master Password' fields.

Description

Verypdf docPrint Pro 8.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized alphanumeric encoded payload in the User Password or Master Password fields. Attackers can craft a malicious payload with encoded shellcode and SEH chain manipulation to bypass protections and execute a MessageBox proof-of-concept when the password fields are processed during PDF encryption.

Exploits (1)

exploitdb WORKING POC
by Connor McGarr · pythonlocalwindows
https://www.exploit-db.com/exploits/47394

This exploit demonstrates a local SEH-based buffer overflow in docPrint Pro v8.0, leveraging alphanumeric shellcode to bypass bad character restrictions and achieve arbitrary code execution via a crafted payload in the 'User/Master Password' fields.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: docPrint Pro v8.0
No auth needed
Prerequisites: docPrint Pro v8.0 installed · local access to the application · a blank PDF file named 'test.pdf'
devstral-2 · analyzed Mar 12, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47394
Various Sources product
http://www.verypdf.com

Scores

CVSS v3 8.4
EPSS 0.0011
EPSS Percentile 1.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
Verypdf/docPrint Pro 8.0
Published Mar 11, 2026
Tracked Since Mar 12, 2026