CVE-2026-7572 Details
Description
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin.
A denial-of-service vulnerability has been identified in Velocidex Velociraptor versions prior to 0.76.5 on Windows and Linux. The issue arises from an off-by-one error in the 'ConsumeUnit16Array' and 'ConsumeUnit64Array' functions, which allows a local attacker to cause a process crash by providing a specially crafted .evtx file to the 'parse_evtx' VQL plugin. This vulnerability only affects users who utilize artifacts that parse EVTX files, as those artifacts will trigger the client crash, which is reported to the server.
Users can upgrade to Velociraptor version 0.76.5 or later. For versions 0.76, upgrade to v0.76.5. Alternatively, switch to collecting raw EVTX files using bulk collection artifacts like 'Windows.Triage.Targets' or 'Windows.Search.FileFinder' and parse the files offline.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.velociraptor.app/announcements/advisories/cve-2026-7572/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-193 | Off-by-one Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rapid7 velociraptor | < 0.76.5 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | [email protected] |