CVE-2015-7358
HIGHCipherShed < 0.7.5.0 and VeraCrypt < 1.15 - Privilege Escalation via Drive Letter Symbolic Link
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-7358. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit leverages a flaw in Truecrypt-derived projects (e.g., VeraCrypt) where the driver incorrectly checks drive letter availability, allowing a local user to remap the system drive via symbolic link manipulation, leading to local privilege escalation.
Description
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.
Exploits (1)
This exploit leverages a flaw in Truecrypt-derived projects (e.g., VeraCrypt) where the driver incorrectly checks drive letter availability, allowing a local user to remap the system drive via symbolic link manipulation, leading to local privilege escalation.
References (6)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H