vendor:
Veracrypt
by:
Google Security Research
7.5
CVSS
HIGH
Local Elevation of Privilege
269
CWE
Product Name: Veracrypt
Affected Version From: Truecrypt 7
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:veracrypt:veracrypt:1.13
Platforms Tested: Windows
Truecrypt 7 Derived Code/Windows: Drive Letter Symbolic Link Creation EoP
The Windows driver used by projects derived from Truecrypt 7 (verified in Veracrypt and CipherShed) are vulnerable to a local elevation of privilege attack by abusing the drive letter symbolic link creation facilities to remap the main system drive. With the system drive remapped it’s trivial to get a new process running under the local system account.
Mitigation:
Apply the patch provided by the vendor.