Impact
A malformed sparse file uploaded by a rogue client can trigger a divide by zero in the Velociraptor GUI component. When the GUI attempts to expand the file, a panic occurs that crashes the server process, resulting in service disruption without affecting data integrity or confidentiality.
Affected Systems
Rapid7 Velociraptor instances that permit user uploads and enable the "Expand Sparse Files" option in the GUI are vulnerable. Version information is not specified; the vulnerability appears to affect all releases that use the impacted ShouldPadFile implementation.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity rating, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a client that gains the ability to upload a malformed sparse file to the server; this does not necessarily require elevated privileges. Exploitation would cause an outright crash of the server process, leading to a denial of service until the process is restarted.
OpenCVE Enrichment