Impact
The CryptoPro Secure Disk for Bitlocker software, prior to version 7.7.4, fails to verify LUKS encrypted partitions. Because the encryption is detected, the program skips all CryptoPro file integrity checks. An attacker who can modify the encrypted data can therefore insert tampered or malicious content without detection, leading to permanent compromise of data integrity.
Affected Systems
The vulnerability affects the CryptoPro Secure Disk for Bitlocker product. Specifically, all releases before v7.7.4 are impacted. No vendor‑provided version list is included in the data, so users should consider any pre‑7.7.4 installation as at risk.
Risk and Exploitability
The CVSS score of 9.1 reflects a critical severity. The EPSS score is less than 1%, indicating a very low but nonzero probability of exploitation. The flaw is listed outside the CISA KEV catalog, indicating no confirmed widespread exploitation. Based on the description, the attack vector is likely local or requires privileged access to the encrypted volume to inject malicious data. Once the integrity checks are bypassed, the attacker could persist tampering that would be treated as legitimate by the system.
OpenCVE Enrichment