{"api_version":"1","generated_at":"2026-07-24T18:40:29+00:00","cve":"CVE-2015-7358","urls":{"html":"https://cve.report/CVE-2015-7358","api":"https://cve.report/api/cve/CVE-2015-7358.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7358","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7358"},"summary":{"title":"CVE-2015-7358","description":"The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-10-03 01:29:00","updated_at":"2021-06-28 18:20:00"},"problem_types":["CWE-264"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2015/09/22/7","name":"[oss-security] 20150922 CVE Request - TrueCrypt 7.1a and VeraCrypt 1.14 Local Elevation of Privilege","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE Request - TrueCrypt 7.1a and VeraCrypt 1.14 Local Elevation of\n Privilege","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://code.google.com/p/google-security-research/issues/detail?id=538","name":"https://code.google.com/p/google-security-research/issues/detail?id=538","refsource":"MISC","tags":["Third Party Advisory"],"title":"Issue 538 - \n google-security-research -\n \n Truecrypt 7 Derived Code/Windows: Drive Letter Symbolic Link Creation EoP - \n Google Security Research - Google Project Hosting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/09/24/3","name":"[oss-security] 20150924 Re: CVE Request - TrueCrypt 7.1a and VeraCrypt 1.14 Local Elevation of Privilege","refsource":"MLIST","tags":["Issue Tracking","Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE Request - TrueCrypt 7.1a and VeraCrypt 1.14 Local Elevation of Privilege","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/133878/Truecrypt-7-Derived-Code-Windows-Drive-Letter-Symbolic-Link-Creation-Privilege-Escalation.html","name":"http://packetstormsecurity.com/files/133878/Truecrypt-7-Derived-Code-Windows-Drive-Letter-Symbolic-Link-Creation-Privilege-Escalation.html","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"Truecrypt 7 Derived Code/Windows: Drive Letter Symbolic Link Creation Privilege Escalation ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://veracrypt.codeplex.com/wikipage?title=Release%20Notes","name":"https://veracrypt.codeplex.com/wikipage?title=Release%20Notes","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"VeraCrypt - Documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/38403/","name":"38403","refsource":"EXPLOIT-DB","tags":["Third Party Advisory","VDB Entry"],"title":"TrueCrypt 7 / VeraCrypt 1.13 - Drive Letter Symbolic Link Creation Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7358","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7358","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7358","vulnerable":"1","versionEndIncluding":"0.7.5.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ciphershed","cpe5":"ciphershed","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7358","vulnerable":"1","versionEndIncluding":"1.14","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"idrix","cpe5":"veracrypt","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7358","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7358","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7358","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"truecrypt","cpe5":"truecrypt","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7358","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"truecrypt","cpe5":"truecrypt","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7358","vulnerable":"1","versionEndIncluding":"1.14","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"veracrypt","cpe5":"veracrypt","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-7358","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://veracrypt.codeplex.com/wikipage?title=Release%20Notes","refsource":"CONFIRM","url":"https://veracrypt.codeplex.com/wikipage?title=Release%20Notes"},{"name":"38403","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/38403/"},{"name":"[oss-security] 20150924 Re: CVE Request - TrueCrypt 7.1a and VeraCrypt 1.14 Local Elevation of Privilege","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/09/24/3"},{"name":"http://packetstormsecurity.com/files/133878/Truecrypt-7-Derived-Code-Windows-Drive-Letter-Symbolic-Link-Creation-Privilege-Escalation.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/133878/Truecrypt-7-Derived-Code-Windows-Drive-Letter-Symbolic-Link-Creation-Privilege-Escalation.html"},{"name":"[oss-security] 20150922 CVE Request - TrueCrypt 7.1a and VeraCrypt 1.14 Local Elevation of Privilege","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/09/22/7"},{"name":"https://code.google.com/p/google-security-research/issues/detail?id=538","refsource":"MISC","url":"https://code.google.com/p/google-security-research/issues/detail?id=538"}]}},"nvd":{"publishedDate":"2017-10-03 01:29:00","lastModifiedDate":"2021-06-28 18:20:00","problem_types":["CWE-264"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ciphershed:ciphershed:*:*:*:*:*:*:*:*","versionEndIncluding":"0.7.5.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:idrix:veracrypt:*:*:*:*:*:*:*:*","versionEndIncluding":"1.14","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:truecrypt:truecrypt:7.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7358","Ordinal":"84363","Title":"CVE-2015-7358","CVE":"CVE-2015-7358","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7358","Ordinal":"1","NoteData":"The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"7358","Ordinal":"2","NoteData":"2017-10-02","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7358","Ordinal":"3","NoteData":"2017-10-02","Type":"Other","Title":"Modified"}]}}}