CVE-2025-59327

CPSD · CryptoPro Secure Disk for Bitlocker

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a flaw where bootxsa.efi fails to validate LUKS encryption, causing file integrity checks to be skipped.

Executive summary

A critical vulnerability in CPSD CryptoPro Secure Disk for Bitlocker allows attackers to bypass file integrity checks by failing to properly validate LUKS encryption during the boot process.

Vulnerability

The vulnerability resides in the bootxsa.efi component, which fails to correctly validate the presence of LUKS encryption. This logic error results in the bypass of critical file integrity checks when encryption is detected, which can be triggered by an unauthenticated attacker.

Business impact

The exploitation of this flaw allows for the circumvention of security controls designed to protect disk integrity. Given the CVSS score of 7.5, this represents a high-severity risk that could lead to unauthorized data access or the persistent compromise of system integrity. Organizations relying on this software for full-disk encryption should treat this as a significant threat to data confidentiality.

Remediation

Immediate Action: Update CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later immediately.

Proactive Monitoring: Monitor system boot logs and integrity audit trails for any anomalous behavior or unexpected bypass events during the initialization phase.

Compensating Controls: Ensure that physical access to the hardware is strictly controlled to prevent unauthorized modification of the boot environment, as this is a prerequisite for exploiting boot-level vulnerabilities.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability in the boot process poses a substantial risk to the security posture of endpoints utilizing CryptoPro Secure Disk. Administrators must prioritize the deployment of the 7.7.4 patch to restore proper integrity validation. Failure to remediate this issue leaves systems susceptible to unauthorized tampering at the boot level, which is difficult to detect once the operating system has loaded.

More CPSD CVEs

Sources