PatchSiren

Idrix CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Idrix CVE published 2017-01-23

CVE-2016-1281

CVE-2016-1281 describes an untrusted search path / DLL hijacking issue in affected installers for TrueCrypt 7.1a and 7.2, and VeraCrypt before 1.17-BETA. The NVD record rates it HIGH (CVSS 7.8) and notes that a local attacker with user interaction could execute code with administrator privileges by placing a Trojan horse DLL in the application directory.