Skip to content
Please update to the latest release 0.77.2 to address Multiple CVEs.

CVE-2026-77797: Velociraptor Prefetch parser out of bounds

Published on 2026-09-21 Vulnogram
Description

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

Problem CWE-20 Improper input validation
Problem CWE-125 Out-of-bounds read
Required configuration for exposure This issue is only exploitable on Windows clients or offline collectors.
Workarounds This issue can result in a client crash. Usually clients will restart after a crash and resume normal operations. Users can collect the raw prefetch files without parsing them on the client for further analysis on the server. 
ProductAffected
Rapid7 Velociraptor on Windows
source repo
Default status is unaffected
before 0.77.3
Credits
  • Yuval Miller and Leon Kayaliev