Vulnerabilities > CVE-2007-1738 - Local Privilege Escalation vulnerability in TrueCrypt Mount Set-EUID

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
truecrypt-foundation
exploit available

Summary

TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589.

Exploit-Db

descriptionTrueCrypt 4.3 Privilege Escalation Exploit (CVE-2007-1738). CVE-2007-1738. Local exploit for windows platform
idEDB-ID:3664
last seen2016-01-31
modified2007-04-04
published2007-04-04
reporterMarco Ivaldi
sourcehttps://www.exploit-db.com/download/3664/
titleTrueCrypt 4.3 - Privilege Escalation Exploit

Seebug

  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:6613
    last seen2017-11-19
    modified2007-04-10
    published2007-04-10
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-6613
    titleTrueCrypt <= 4.3 Local Privilege Escalation Exploit (CVE-2007-1738)
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:64601
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-64601
    titleTrueCrypt 4.3 - Privilege Escalation Exploit