CVE-2025-59323
CPSD · CryptoPro Secure Disk for Bitlocker
CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 fails to validate DataStore integrity, potentially allowing local attackers to achieve high privilege code execution or cause service failure.
Executive summary
A critical integrity validation flaw in CPSD CryptoPro Secure Disk for Bitlocker allows unauthenticated local attackers to execute arbitrary code with high privileges.
Vulnerability
The software fails to perform integrity checks on the DataStore, which is a non-partitioned filesystem used for configuration and cryptographic data. An attacker can supply a crafted DataStore to achieve local code execution or cause a denial of service, requiring no authentication.
Business impact
The ability for an unauthenticated local user to gain high privilege code execution represents a total compromise of the affected host. Given the CVSS score of 8.4, this vulnerability poses a severe threat to data confidentiality, integrity, and availability, potentially allowing attackers to bypass disk encryption protections and access sensitive information.
Remediation
Immediate Action: Update CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later immediately.
Proactive Monitoring: Monitor system logs for unusual file access patterns related to the DataStore or unexpected service restarts that may indicate attempted manipulation.
Compensating Controls: Limit physical and local access to systems running this software, as the vulnerability requires local access to the target environment to exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing CPSD CryptoPro Secure Disk for Bitlocker must prioritize upgrading to version 7.7.4 to remediate this critical flaw. Failure to patch allows local users to potentially escalate privileges and compromise the entire cryptographic security posture of the host, necessitating immediate administrative action.