Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g.  dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.  If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
History

Tue, 11 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g.  dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.  If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
Title Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes
Weaknesses CWE-125
CWE-369
CWE-789
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-08-11T14:47:13.859Z

Reserved: 2026-07-27T09:21:41.141Z

Link: CVE-2026-17535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T15:17:27.927

Modified: 2026-08-11T15:17:27.927

Link: CVE-2026-17535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.