Home

Description

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin.

PUBLISHED Reserved 2026-05-01 | Published 2026-05-06 | Updated 2026-05-06 | Assigner rapid7




MEDIUM: 4.4CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Problem types

CWE-193: Off-by-one Error

Product status

Default status
unaffected

Any version before 0.76.5
affected

References

docs.velociraptor.app/...uncements/advisories/cve-2026-7572/ vendor-advisory

cve.org (CVE-2026-7572)

nvd.nist.gov (CVE-2026-7572)

Download JSON