CVE-2026-7572
Velociraptor vulnerability analysis and mitigation

Overview

CVE-2026-7572 is an off-by-one error (CWE-193) in Velocidex Velociraptor's ConsumeUnit16Array and ConsumeUnit64Array functions that allows a local attacker to crash the Velociraptor process via a specially crafted .evtx file. It affects all versions of Velociraptor before 0.76.5 on both Windows and Linux. The vulnerability was published on May 6, 2026, with a patch released in version 0.76.5. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, and 4.4 (Moderate) per GitHub Advisory (GitHub Advisory, Velociraptor Advisory).

Technical details

The root cause is an off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions within Velociraptor's Windows Event Log (EVTX) parser. When the parse_evtx VQL plugin processes a maliciously crafted .evtx file, the incorrect boundary calculation in these functions leads to an out-of-bounds memory access, ultimately causing a process crash. Exploitation requires the attacker to supply a crafted .evtx file and have a user or automated process invoke the parse_evtx plugin against it — no special privileges are required, but user interaction (or equivalent automation) is needed (GitHub Advisory, Velociraptor Advisory).

Impact

Successful exploitation results in a Denial of Service (DoS) through a crash of the Velociraptor process, disrupting endpoint visibility and forensic/incident response capabilities on affected Windows and Linux systems. There is no impact on confidentiality or data integrity (per NVD scoring), and no evidence of lateral movement potential. The primary risk is the loss of Velociraptor's monitoring and investigation functionality during an active incident response engagement (GitHub Advisory).

Exploitation steps

  1. Craft a malicious .evtx file: Create a specially crafted Windows Event Log file that triggers the off-by-one boundary error in the ConsumeUnit16Array or ConsumeUnit64Array parsing functions.
  2. Deliver the file to the target system: Place the crafted .evtx file in a location accessible to the Velociraptor agent or analyst (e.g., a monitored directory, a shared network path, or via social engineering).
  3. Trigger parse_evtx processing: Cause the parse_evtx VQL plugin to process the malicious file — this could occur through a scheduled VQL hunt, an analyst manually running a query, or an automated artifact collection targeting .evtx files.
  4. Achieve DoS: The off-by-one error causes an out-of-bounds memory access, crashing the Velociraptor process and disrupting endpoint monitoring and forensic capabilities (GitHub Advisory, Velociraptor Advisory).

Indicators of compromise

  • Process: Unexpected termination or crash of the Velociraptor agent/server process (velociraptor.exe on Windows or velociraptor on Linux) without a clear administrative cause.
  • Logs: Crash dump files or panic stack traces in Velociraptor log output referencing ConsumeUnit16Array or ConsumeUnit64Array functions; Go runtime panic messages associated with out-of-bounds memory access.
  • File System: Presence of an unusual or externally supplied .evtx file in directories monitored or processed by Velociraptor; unexpected .evtx files in temporary or artifact collection directories.
  • Network: Absence of expected Velociraptor heartbeat or check-in traffic from an endpoint following the introduction of a crafted .evtx file.

Mitigation and workarounds

Upgrade Velocidex Velociraptor to version 0.76.5 or later on all affected Windows and Linux systems, as this version contains the fix for the off-by-one error (GitHub Advisory, Velociraptor Advisory). As a temporary workaround, restrict access to the parse_evtx VQL plugin and validate or sanitize .evtx files before processing them through Velociraptor. Limit the ability of untrusted users to supply .evtx files to Velociraptor collection workflows.

Additional resources


SourceThis report was generated using AI

Related Velociraptor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6290CRITICAL9.1
  • Velociraptor logoVelociraptor
  • www.velocidex.com/golang/velociraptor
NoYesApr 15, 2026
CVE-2026-8795HIGH7.8
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesJun 09, 2026
CVE-2026-7573HIGH7.7
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesMay 06, 2026
CVE-2026-7572MEDIUM5.5
  • Velociraptor logoVelociraptor
  • www.velocidex.com/golang/velociraptor
NoYesMay 06, 2026
CVE-2026-6948MEDIUM4.9
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management