Velociraptor Prefetch parser out of bounds
Summary
| CVE | CVE-2026-77797 |
|---|---|
| State | PUBLISHED |
| Assigner | rapid7 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-24 14:18:17 UTC |
| Updated | 2026-09-24 21:00:46 UTC |
| Description | Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files. |
Risk And Classification
Primary CVSS: v3.1 3.6 LOW from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Problem Types: CWE-20 | CWE-125 | CWE-20 CWE-20 Improper input validation | CWE-125 CWE-125 Out-of-bounds read
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 3.6 | LOW | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 3.6 | LOW | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rapid7 | Velociraptor | affected 0.77.3 semver | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/Velocidex/go-prefetch/commit/4bae9796298011598d577b125e0b3db3... | [email protected] | github.com | |
| docs.velociraptor.app/announcements/advisories/cve-2026-7797 | [email protected] | docs.velociraptor.app | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Yuval Miller and Leon Kayaliev (en)
Additional Advisory Data
Workarounds
CNA: This issue can result in a client crash. Usually clients will restart after a crash and resume normal operations. Users can collect the raw prefetch files without parsing them on the client for further analysis on the server.
There are currently no legacy QID mappings associated with this CVE.