Impact
CPSD CryptoPro Secure Disk for Bitlocker prior to version 7.7.4 fails to confirm the authenticity of the intended boot partition and instead selects the first partition index that matches a hard‑coded type value. This flaw permits an attacker to craft a Linux partition and place it ahead of the desired boot target. When the system initiates the boot process, the malicious partition is selected, enabling the attacker to execute code with elevated privileges. The weakness represents an authentication bypass (CWE‑290) that disrupts the integrity guarantees of the boot environment and permits remote code execution within a high‑privilege context.
Affected Systems
All installations of CPSD CryptoPro Secure Disk for Bitlocker released before version 7.7.4 are vulnerable. Systems that rely on this software to protect boot media must be considered at risk until the patch is applied or an equivalent mitigation is enforced.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so the current likelihood of exploitation is unknown. The attack requires the ability to alter the order or content of disk partitions, which suggests either local or physical access. An attacker with such access can place the crafted partition in the machine’s storage, provoke the flawed selection logic, and gain elevated execution rights. The absence of an official fix in the supplied data means operators must consider patching to v7.7.4 or applying alternative controls.
OpenCVE Enrichment