CVE-2026-17535
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
11/08/2026
Last modified:
11/08/2026
Description
Velociraptor&#39;s NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images.<br />
<br />
Typically Velociraptor&#39;s NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files. <br />
<br />
If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
Impact
Base Score 3.x
6.20
Severity 3.x
MEDIUM


