Vulnerability CVE-2015-7359


Published: 2017-10-02   Modified: 2017-10-03

Description:
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impersonate a user at SecurityIdentify level and gain access to other users' mounted encrypted volumes.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Veracrypt -> Veracrypt 
Truecrypt -> Truecrypt 
Ciphershed -> Ciphershed 

 References:
http://packetstormsecurity.com/files/133877/Truecrypt-7-Privilege-Escalation.html
http://www.openwall.com/lists/oss-security/2015/09/22/7
http://www.openwall.com/lists/oss-security/2015/09/24/3
https://code.google.com/p/google-security-research/issues/detail?id=537
https://veracrypt.codeplex.com/wikipage?title=Release%20Notes

Copyright 2024, cxsecurity.com

 

Back to Top