CVE-2016-1281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
23/01/2017
Last modified:
20/04/2025

Description

Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Trojan horse DLL in the "application directory", as demonstrated with the USP10.dll, RichEd20.dll, NTMarta.dll and SRClient.dll DLLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:idrix:truecrypt:7.1:a:*:*:*:*:*:*
cpe:2.3:a:idrix:truecrypt:7.2:*:*:*:*:*:*:*
cpe:2.3:a:idrix:veracrypt:*:*:*:*:*:*:*:* 1.16 (including)