First published: Mon Mar 19 2018(Updated: )
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
TrueCrypt | =7.1-a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2884 is considered a high severity vulnerability due to its potential for local users to bypass access restrictions.
The only effective fix for CVE-2014-2884 is to stop using TrueCrypt 7.1a and migrate to a more secure alternative.
CVE-2014-2884 affects all local users of TrueCrypt version 7.1a who have access to exploit the vulnerable IOCTL calls.
CVE-2014-2884 may allow local users to access sensitive information about arbitrary files on the system.
CVE-2014-2884 specifically impacts the ProcessVolumeDeviceControlIrp function in Ntdriver.c.