CVE-2015-7358 is a local privilege escalation vulnerability affecting TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed on Windows. The flaw lies in the IsDriveLetterAvailable method, which fails to properly validate drive letter symbolic links, allowing a local attacker to mount an encrypted volume over an existing drive letter and gain privileges via the /GLOBAL?? directory. This vulnerability carries a CVSS v3 score of 7.8 (High), indicating a significant risk. It requires local access and low privileges, but once exploited, it can lead to high confidentiality, integrity, and availability impacts. The attack complexity is low, making it relatively easy to exploit for an authenticated local user. While not listed on the CISA KEV catalog, exploit code for this vulnerability, specifically EDB-38403, is publicly available on ExploitDB. There is also community discussion and media coverage surrounding this flaw, suggesting awareness among security researchers and the public.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7.5.0CPE matchmatch criteria | cpe:2.3:a:ciphershed:ciphershed:*:*:*:*:*:*:*:* | ||
<= 1.14CPE matchmatch criteria | cpe:2.3:a:idrix:veracrypt:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:truecrypt:truecrypt:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.