CVE-2025-59324
CPSD · CryptoPro Secure Disk for Bitlocker
CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 fails to validate LUKS encryption, causing the software to bypass critical file integrity checks when such encryption is detected.
Executive summary
A critical vulnerability in CPSD CryptoPro Secure Disk for Bitlocker allows unauthenticated attackers to bypass file integrity checks, potentially leading to unauthorized data modification or access.
Vulnerability
The software fails to properly validate LUKS encryption, which leads to the omission of all CryptoPro file integrity checks for encrypted volumes. This flaw is remotely exploitable by an unauthenticated attacker.
Business impact
The vulnerability carries a CVSS score of 9.1, reflecting its critical nature and ease of exploitation. By bypassing integrity checks, an attacker could potentially manipulate encrypted data without detection, leading to severe risks regarding data confidentiality and integrity. This poses a significant threat to organizational data security and compliance requirements.
Remediation
Immediate Action: Upgrade all instances of CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later immediately.
Proactive Monitoring: Review system logs for unusual file access patterns or unauthorized attempts to modify encrypted partitions.
Compensating Controls: Ensure that secondary integrity verification tools are in place and that sensitive environments are isolated from untrusted networks to minimize the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical severity of this flaw and the potential for unauthenticated exploitation, immediate action is required. Administrators should prioritize upgrading to version 7.7.4 to restore file integrity protections. Failure to patch this vulnerability leaves encrypted storage systems exposed to silent data manipulation and unauthorized access.