CVE-2019-1010208: Idrix Truecrypt

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The component is: Veracrypt NT Driver (veracrypt.sys). The attack vector is: Locally executed code, IOCTL request to driver. The fixed version is: 1.23-Hotfix-1.

Affected products

  • Idrix Truecrypt: any version
  • Idrix Veracrypt: up to and including 1.23

Published 2019-07-23. Last modified 2026-06-17.