PT-2019-11513 · Truecrypt Foundation+1 · Truecrypt+1

Tim Harrison

·

Publicado

2019-07-23

·

Atualizado

2021-02-19

·

CVE-2019-1010208

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Veracrypt versions prior to 1.23-Hotfix-1 Truecrypt all versions
Description: The issue is related to a buffer overflow in the Veracrypt NT Driver (veracrypt.sys) component, which can lead to minor information disclosure of the kernel stack. This can be exploited through locally executed code by sending an IOCTL request to the driver.
Recommendations: For Veracrypt versions prior to 1.23-Hotfix-1, update to version 1.23-Hotfix-1 to resolve the issue. For Truecrypt, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Veracrypt NT Driver (veracrypt.sys) to minimize the risk of exploitation.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1010208
MGASA-2021-0088

Produtos afetados

Truecrypt
Veracrypt