5.5
CVE-2026-7572
- EPSS 0.14%
- Veröffentlicht 06.05.2026 03:15:58
- Zuletzt bearbeitet 01.06.2026 16:59:31
- Quelle cve@rapid7.com
- CVE-Watchlists
- Unerledigt
Velociraptor EVTX Parser — Process Crash via Crafted .evtx File
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx VQL plugin.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rapid7 ≫ Velociraptor Version < 0.76.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.038 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| cve@rapid7.com | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
|
CWE-193 Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
https://docs.velociraptor.app/announcements/advisories/cve-2026-7572/