Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
Published: 2026-08-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CPSD CryptoPro Secure Disk for Bitlocker prior to version 7.7.4 fails to confirm the authenticity of the intended boot partition and instead selects the first partition index that matches a hard‑coded type value. This flaw permits an attacker to craft a Linux partition and place it ahead of the desired boot target. When the system initiates the boot process, the malicious partition is selected, enabling the attacker to execute code with elevated privileges. The weakness represents an authentication bypass (CWE‑290) that disrupts the integrity guarantees of the boot environment and permits remote code execution within a high‑privilege context.

Affected Systems

All installations of CPSD CryptoPro Secure Disk for Bitlocker released before version 7.7.4 are vulnerable. Systems that rely on this software to protect boot media must be considered at risk until the patch is applied or an equivalent mitigation is enforced.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so the current likelihood of exploitation is unknown. The attack requires the ability to alter the order or content of disk partitions, which suggests either local or physical access. An attacker with such access can place the crafted partition in the machine’s storage, provoke the flawed selection logic, and gain elevated execution rights. The absence of an official fix in the supplied data means operators must consider patching to v7.7.4 or applying alternative controls.

Generated by OpenCVE AI on August 12, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CPSD CryptoPro Secure Disk to version 7.7.4 or later to eliminate the boot‑partition selection flaw.
  • If an update is not immediately feasible, restrict physical and logical access to the system’s storage to prevent unauthorized partition insertion.
  • Implement monitoring to detect changes in boot‑partition ordering or unexpected partitions and enforce disk integrity policies according to vendor recommendations.

Generated by OpenCVE AI on August 12, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Secure Disk
Vendors & Products Cpsd
Cpsd cryptopro Secure Disk

Wed, 12 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Boot Partition Selection in CryptoPro Secure Disk

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
References

Subscriptions

Cpsd Cryptopro Secure Disk
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-12T19:24:46.816Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59319

cve-icon Vulnrichment

Updated: 2026-08-12T19:24:41.206Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T15:17:28.963

Modified: 2026-08-31T19:33:11.197

Link: CVE-2025-59319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:45:02Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing