Impact
An uncontrolled recursion in the Windows SIPA event log parser can cause a Go stack overflow, crashing the verifier application. The vulnerability occurs when the parser recurses for every nested elamAggregation sub‑event without limiting depth, allowing an attacker to craft a deeply nested event log that exhausts the call stack. The resulting unrecoverable fatal error leads to a denial of service, impacting the availability of the verifier and any services that rely on it. The weakness is classified as CWE‑674.
Affected Systems
Google’s go‑attestation library, versions up to and including 0.6.1, is affected. Users of any application that embeds this library and processes Windows event logs through the SIPA parser must consider the risk. No other vendor or product versions are listed in the current data.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack requires an attacker who can supply a crafted Windows event log to the verifier; if the verifier runs with elevated privileges, the crash could affect the host system. Because the issue is a stack overflow caused by unbounded recursion, it is less likely to be remotely exploitable without direct input but remains a significant availability risk for affected deployments.
OpenCVE Enrichment