CVE-2015-7358: Ciphershed

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.

Affected products

  • Ciphershed Ciphershed: up to and including 0.7.5.0
  • Idrix Veracrypt: up to and including 1.14
  • Truecrypt Truecrypt: version 7.0 only

Published 2017-10-03. Last modified 2026-06-17.