CVE-2015-7358

HIGH

CipherShed < 0.7.5.0 and VeraCrypt < 1.15 - Privilege Escalation via Drive Letter Symbolic Link

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7358. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit leverages a flaw in Truecrypt-derived projects (e.g., VeraCrypt) where the driver incorrectly checks drive letter availability, allowing a local user to remap the system drive via symbolic link manipulation, leading to local privilege escalation.

Description

The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textlocalwindows_x86
https://www.exploit-db.com/exploits/38403

This exploit leverages a flaw in Truecrypt-derived projects (e.g., VeraCrypt) where the driver incorrectly checks drive letter availability, allowing a local user to remap the system drive via symbolic link manipulation, leading to local privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: VeraCrypt 1.13 (and other Truecrypt-derived projects)
Auth required
Prerequisites: Local user access · VeraCrypt volume file · Password for the volume
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://veracrypt.codeplex.com/wikipage?title=Release%20Notes
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38403/
Issue Tracking, Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/24/3
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/09/22/7

Scores

CVSS v3 7.8
EPSS 0.0120
EPSS Percentile 64.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (3)
ciphershed/ciphershed < 0.7.5.0
idrix/veracrypt < 1.14
truecrypt/truecrypt 7.0
Published Oct 03, 2017
Tracked Since Feb 18, 2026