CVE-2015-7358

The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ciphershed:ciphershed:*:*:*:*:*:*:*:*
cpe:2.3:a:idrix:veracrypt:*:*:*:*:*:*:*:*
cpe:2.3:a:truecrypt:truecrypt:7.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:36

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/133878/Truecrypt-7-Derived-Code-Windows-Drive-Letter-Symbolic-Link-Creation-Privilege-Escalation.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/133878/Truecrypt-7-Derived-Code-Windows-Drive-Letter-Symbolic-Link-Creation-Privilege-Escalation.html - Third Party Advisory, VDB Entry
References () http://www.openwall.com/lists/oss-security/2015/09/22/7 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/09/22/7 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2015/09/24/3 - Issue Tracking, Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/09/24/3 - Issue Tracking, Mailing List, Third Party Advisory
References () https://code.google.com/p/google-security-research/issues/detail?id=538 - Third Party Advisory () https://code.google.com/p/google-security-research/issues/detail?id=538 - Third Party Advisory
References () https://veracrypt.codeplex.com/wikipage?title=Release%20Notes - Release Notes, Vendor Advisory () https://veracrypt.codeplex.com/wikipage?title=Release%20Notes - Release Notes, Vendor Advisory
References () https://www.exploit-db.com/exploits/38403/ - Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/38403/ - Third Party Advisory, VDB Entry

Information

Published : 2017-10-03 01:29

Updated : 2024-11-21 02:36


NVD link : CVE-2015-7358

Mitre link : CVE-2015-7358

CVE.ORG link : CVE-2015-7358


JSON object : View

Products Affected

microsoft

  • windows

truecrypt

  • truecrypt

idrix

  • veracrypt

ciphershed

  • ciphershed
CWE
CWE-264

Permissions, Privileges, and Access Controls