Vulnerability Description
IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The component is: Veracrypt NT Driver (veracrypt.sys). The attack vector is: Locally executed code, IOCTL request to driver. The fixed version is: 1.23-Hotfix-1.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Idrix | Truecrypt | All versions |
| Idrix | Veracrypt | <= 1.23 |
Related Weaknesses (CWE)
References
- https://github.com/veracrypt/VeraCrypt/commit/f30f9339c9a0b9bbcc6f5ad38804af39dbPatchThird Party Advisory
- https://github.com/veracrypt/VeraCrypt/commit/f30f9339c9a0b9bbcc6f5ad38804af39dbPatchThird Party Advisory
FAQ
What is CVE-2019-1010208?
CVE-2019-1010208 is a vulnerability with a CVSS score of 3.3 (LOW). IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The com...
How severe is CVE-2019-1010208?
CVE-2019-1010208 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010208?
Check the references section above for vendor advisories and patch information. Affected products include: Idrix Truecrypt, Idrix Veracrypt.