Impact
CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 does not verify the integrity of its DataStore, a non‑partitioned filesystem that stores configuration and cryptographic information. By supplying crafted DataStore contents an attacker can disrupt service availability or execute code with administrative privileges, potentially compromising the entire system. The weakness arises from improper validation of stored data.
Affected Systems
CPSD CryptoPro Secure Disk for Bitlocker versions older than 7.7.4, including 7.7.3 and earlier, use the vulnerable DataStore mechanism.
Risk and Exploitability
The flaw carries a CVSS score of 8.4, an EPSS score below 1 %, and is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires local access to modify the DataStore file, meaning a local attacker with write permissions can trigger the vulnerability, resulting in high‑privilege code execution or denial of service.
OpenCVE Enrichment