Impact
CryptoPro Secure Disk for Bitlocker fails to properly process decryption errors, enabling an attacker to mount an encrypted volume as plaintext. The flaw effectively bypasses Bitlocker encryption, exposing the sensitive data stored on the volume. The primary impact is a loss of confidentiality, allowing unauthorized reading of encrypted data. The weakness arises from inadequate error handling during decryption, which the software does not handle securely.
Affected Systems
The vulnerability affects CPSD's CryptoPro Secure Disk for Bitlocker installations earlier than version 7.7.4. Systems running any pre‑7.7.4 release are at risk. No alternative versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact vulnerability, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no known publicly curated exploits have been observed yet. The flaw allows an attacker who can trigger a decryption failure to mount an encrypted volume as plaintext, providing high confidentiality impact. The likely attack vector is local, requiring the attacker to initiate a decryption error on a CryptoPro‑managed volume, though an external exploitation path cannot be ruled out without further evidence.
OpenCVE Enrichment