Vulnerability Details CVE-2019-1010208
IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The component is: Veracrypt NT Driver (veracrypt.sys). The attack vector is: Locally executed code, IOCTL request to driver. The fixed version is: 1.23-Hotfix-1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.5%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 2.1
Products affected by CVE-2019-1010208
-
cpe:2.3:a:idrix:truecrypt:7.1
-
cpe:2.3:a:idrix:truecrypt:7.2
-
cpe:2.3:a:idrix:veracrypt:1.0a
-
cpe:2.3:a:idrix:veracrypt:1.0b
-
cpe:2.3:a:idrix:veracrypt:1.0c
-
cpe:2.3:a:idrix:veracrypt:1.0d
-
cpe:2.3:a:idrix:veracrypt:1.0e
-
cpe:2.3:a:idrix:veracrypt:1.0f
-
cpe:2.3:a:idrix:veracrypt:1.0f-1
-
cpe:2.3:a:idrix:veracrypt:1.0f-2
-
cpe:2.3:a:idrix:veracrypt:1.12
-
cpe:2.3:a:idrix:veracrypt:1.13
-
cpe:2.3:a:idrix:veracrypt:1.14
-
cpe:2.3:a:idrix:veracrypt:1.15
-
cpe:2.3:a:idrix:veracrypt:1.16
-
cpe:2.3:a:idrix:veracrypt:1.17
-
cpe:2.3:a:idrix:veracrypt:1.18
-
cpe:2.3:a:idrix:veracrypt:1.18a
-
cpe:2.3:a:idrix:veracrypt:1.19
-
cpe:2.3:a:idrix:veracrypt:1.20
-
cpe:2.3:a:idrix:veracrypt:1.21
-
cpe:2.3:a:idrix:veracrypt:1.22
-
cpe:2.3:a:idrix:veracrypt:1.23