CVE-2026-7572

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:rapid7:velociraptor:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-06 03:15

Updated : 2026-07-24 08:10


NVD link : CVE-2026-7572

Mitre link : CVE-2026-7572

CVE.ORG link : CVE-2026-7572


JSON object : View

Products Affected

rapid7

  • velociraptor

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-193

Off-by-one Error