Impact
CPSD CryptoPro Secure Disk for Bitlocker fails to enforce Integrity Measurement Architecture (IMA) policy protections across temporary file systems, which permits unsigned code to be executed from these locations. The flaw arises because the product does not validate or restrict execution of code that is stored on temporary storage, allowing an attacker to run code without regard to the signedness of the executable.
Affected Systems
Versions of CPSD CryptoPro Secure Disk for Bitlocker before 7.7.4 are affected. No other vendors or products are listed in the official CNA data.
Risk and Exploitability
A CVSS score of 9.8 signifies critical severity, while an EPSS score of < 1% indicates a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker with write access to a temporary file system could place malicious code that would be executed because IMA policy enforcement is bypassed. No additional prerequisites are stated in the CVE data.
OpenCVE Enrichment