CVE-2025-59326
9.8CPSD · CryptoPro Secure Disk for Bitlocker
CPSD CryptoPro Secure Disk for Bitlocker fails to enforce IMA policy protections on temporary file systems, enabling the execution of unsigned code.
Executive summary
A critical vulnerability in CPSD CryptoPro Secure Disk for Bitlocker allows unauthenticated attackers to execute arbitrary unsigned code, posing a severe risk of total system compromise.
Vulnerability
The software fails to properly enforce Integrity Measurement Architecture (IMA) policy protections across temporary file systems. This allows an unauthenticated attacker to bypass security controls and execute unsigned code on the host system.
Business impact
The ability to execute unsigned code grants an attacker full control over the affected system, leading to potential data exfiltration, malware installation, and complete loss of confidentiality, integrity, and availability. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it provides an unauthenticated remote attacker with a path to total system takeover without requiring user interaction.
Remediation
Immediate Action: Organizations using CPSD CryptoPro Secure Disk for Bitlocker must upgrade to version 7.7.4 or later immediately to apply the necessary IMA policy enforcement.
Proactive Monitoring: Security teams should monitor system logs for signs of unauthorized file execution or unexpected processes originating from temporary directories, such as /tmp or /var/tmp.
Compensating Controls: Implement strict file system permissions and execution policies to restrict the ability to run binaries from temporary locations until the software update can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and the potential for total system compromise, this vulnerability requires immediate attention. Administrators should prioritize patching to version 7.7.4 or higher across all affected environments to eliminate the risk of unauthorized code execution.