CVE-2025-59321

CPSD · CryptoPro Secure Disk for Bitlocker

CPSD CryptoPro Secure Disk for Bitlocker before 7.7.4 contains a flaw in the TPM PCR policy, allowing unauthorized unsealing of the TPM and potential bypass of disk encryption protections.

Executive summary

A critical vulnerability in CPSD CryptoPro Secure Disk for Bitlocker allows unauthenticated attackers to bypass disk encryption by unsealing the TPM via an improper boot state policy.

Vulnerability

The software implements an insecure default Trusted Platform Module (TPM) Platform Configuration Register (PCR) policy that fails to validate the system boot state. This allows an unauthenticated attacker to unseal the TPM and access encrypted data, either through an unintended execution path or by migrating the encrypted drive to unauthorized hardware.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of data confidentiality and integrity for systems utilizing affected encryption software. Given the CVSS score of 9.8, this represents a critical risk where an attacker can bypass full disk encryption, potentially leading to unauthorized access to sensitive corporate information, intellectual property, and system credentials.

Remediation

Immediate Action: Upgrade to CPSD CryptoPro Secure Disk for Bitlocker version 7.7.4 or later immediately to implement a secure TPM PCR policy.

Proactive Monitoring: Audit system logs for unexpected TPM state changes or repeated, unauthorized attempts to access encrypted volumes during the boot sequence.

Compensating Controls: Ensure secondary authentication methods, such as pre-boot PINs or physical hardware tokens, are enforced to provide defense in depth until patches are applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a severe risk to organizational data security by invalidating the primary encryption protections of the affected systems. Security teams must prioritize patching to version 7.7.4 across all deployed instances to ensure the TPM correctly validates the boot state before allowing disk access.

More CPSD CVEs

Sources