An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin.
References
| Link | Resource |
|---|---|
| https://docs.velociraptor.app/announcements/advisories/cve-2026-7572/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-06 03:15
Updated : 2026-07-24 08:10
NVD link : CVE-2026-7572
Mitre link : CVE-2026-7572
CVE.ORG link : CVE-2026-7572
JSON object : View
Products Affected
rapid7
- velociraptor
microsoft
- windows
linux
- linux_kernel
CWE
CWE-193
Off-by-one Error
