Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Trojan horse DLL in the "application directory", as demonstrated with the USP10.dll, RichEd20.dll, NTMarta.dll and SRClient.dll DLLs.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "7.1-a"
},
{
"last_affected": "7.1-a"
},
{
"introduced": "7.2"
},
{
"last_affected": "7.2"
}
],
"cpes": [
"cpe:2.3:a:idrix:truecrypt:7.1:a:*:*:*:*:*:*",
"cpe:2.3:a:idrix:truecrypt:7.2:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "idrix:truecrypt"
}
]
}{
"cpe": "cpe:2.3:a:idrix:veracrypt:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.16"
}
],
"source": "CPE_RANGE"
}