Vulnerability Description
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impersonate a user at SecurityIdentify level and gain access to other users' mounted encrypted volumes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ciphershed | Ciphershed | <= 0.7.5.0 |
| Idrix | Veracrypt | <= 1.14 |
| Truecrypt | Truecrypt | 7.0 |
| Microsoft | Windows | All versions |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/133877/Truecrypt-7-Privilege-Escalation.htmThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2015/09/22/7Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/09/24/3Issue TrackingMailing ListThird Party Advisory
- https://code.google.com/p/google-security-research/issues/detail?id=537Issue TrackingThird Party Advisory
- https://veracrypt.codeplex.com/wikipage?title=Release%20NotesRelease NotesVendor Advisory
- http://packetstormsecurity.com/files/133877/Truecrypt-7-Privilege-Escalation.htmThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2015/09/22/7Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2015/09/24/3Issue TrackingMailing ListThird Party Advisory
- https://code.google.com/p/google-security-research/issues/detail?id=537Issue TrackingThird Party Advisory
- https://veracrypt.codeplex.com/wikipage?title=Release%20NotesRelease NotesVendor Advisory
FAQ
What is CVE-2015-7359?
CVE-2015-7359 is a vulnerability with a CVSS score of 7.8 (HIGH). The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level...
How severe is CVE-2015-7359?
CVE-2015-7359 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7359?
Check the references section above for vendor advisories and patch information. Affected products include: Ciphershed Ciphershed, Idrix Veracrypt, Truecrypt Truecrypt, Microsoft Windows.