
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7572 is an off-by-one error (CWE-193) in Velocidex Velociraptor's ConsumeUnit16Array and ConsumeUnit64Array functions that allows a local attacker to crash the Velociraptor process via a specially crafted .evtx file. It affects all versions of Velociraptor before 0.76.5 on both Windows and Linux. The vulnerability was published on May 6, 2026, with a patch released in version 0.76.5. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, and 4.4 (Moderate) per GitHub Advisory (GitHub Advisory, Velociraptor Advisory).
The root cause is an off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions within Velociraptor's Windows Event Log (EVTX) parser. When the parse_evtx VQL plugin processes a maliciously crafted .evtx file, the incorrect boundary calculation in these functions leads to an out-of-bounds memory access, ultimately causing a process crash. Exploitation requires the attacker to supply a crafted .evtx file and have a user or automated process invoke the parse_evtx plugin against it — no special privileges are required, but user interaction (or equivalent automation) is needed (GitHub Advisory, Velociraptor Advisory).
Successful exploitation results in a Denial of Service (DoS) through a crash of the Velociraptor process, disrupting endpoint visibility and forensic/incident response capabilities on affected Windows and Linux systems. There is no impact on confidentiality or data integrity (per NVD scoring), and no evidence of lateral movement potential. The primary risk is the loss of Velociraptor's monitoring and investigation functionality during an active incident response engagement (GitHub Advisory).
ConsumeUnit16Array or ConsumeUnit64Array parsing functions..evtx file in a location accessible to the Velociraptor agent or analyst (e.g., a monitored directory, a shared network path, or via social engineering).parse_evtx VQL plugin to process the malicious file — this could occur through a scheduled VQL hunt, an analyst manually running a query, or an automated artifact collection targeting .evtx files.velociraptor.exe on Windows or velociraptor on Linux) without a clear administrative cause.ConsumeUnit16Array or ConsumeUnit64Array functions; Go runtime panic messages associated with out-of-bounds memory access..evtx file in directories monitored or processed by Velociraptor; unexpected .evtx files in temporary or artifact collection directories..evtx file.Upgrade Velocidex Velociraptor to version 0.76.5 or later on all affected Windows and Linux systems, as this version contains the fix for the off-by-one error (GitHub Advisory, Velociraptor Advisory). As a temporary workaround, restrict access to the parse_evtx VQL plugin and validate or sanitize .evtx files before processing them through Velociraptor. Limit the ability of untrusted users to supply .evtx files to Velociraptor collection workflows.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."