CVE-2014-2884: Infoleak
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TCIOCTLOPENTEST or (2) TCIOCTLGETSYSTEMDRIVECONFIG IOCTL call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2884?
CVE-2014-2884 is considered a high severity vulnerability due to its potential for local users to bypass access restrictions.
How do I fix CVE-2014-2884?
The only effective fix for CVE-2014-2884 is to stop using TrueCrypt 7.1a and migrate to a more secure alternative.
Who is affected by CVE-2014-2884?
CVE-2014-2884 affects all local users of TrueCrypt version 7.1a who have access to exploit the vulnerable IOCTL calls.
What type of information can be exposed due to CVE-2014-2884?
CVE-2014-2884 may allow local users to access sensitive information about arbitrary files on the system.
What components of TrueCrypt are impacted by CVE-2014-2884?
CVE-2014-2884 specifically impacts the ProcessVolumeDeviceControlIrp function in Ntdriver.c.