Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.
Published: 2026-08-12
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CPSD CryptoPro Secure Disk for Bitlocker fails to enforce Integrity Measurement Architecture (IMA) policy protections across temporary file systems, which permits unsigned code to be executed from these locations. The flaw arises because the product does not validate or restrict execution of code that is stored on temporary storage, allowing an attacker to run code without regard to the signedness of the executable.

Affected Systems

Versions of CPSD CryptoPro Secure Disk for Bitlocker before 7.7.4 are affected. No other vendors or products are listed in the official CNA data.

Risk and Exploitability

A CVSS score of 9.8 signifies critical severity, while an EPSS score of < 1% indicates a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker with write access to a temporary file system could place malicious code that would be executed because IMA policy enforcement is bypassed. No additional prerequisites are stated in the CVE data.

Generated by OpenCVE AI on August 13, 2026 at 21:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to CPSD CryptoPro Secure Disk for Bitlocker v7.7.4 or later, which restores IMA policy enforcement across temporary file systems.
  • If upgrading is not immediately possible, configure the operating system to deny execution of code from temporary directories, for example by adding a noexec mount option or otherwise restricting executable permission on those paths.
  • Regularly audit and enforce IMA policies across all mount points, ensuring that integrity checks are applied to newly created files in transient storage.

Generated by OpenCVE AI on August 13, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title CPSD Secure Disk for Bitlocker Bypasses IMA Policy, Allowing Unsigned Code Execution from Temporary Files

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unsigned Code Execution via Temporary File System in CPSD CryptoPro Secure Disk Prior to v7.7.4
Weaknesses CWE-264
CWE-285

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Secure Disk
Vendors & Products Cpsd
Cpsd cryptopro Secure Disk

Thu, 13 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unsigned Code Execution via Temporary File System in CPSD CryptoPro Secure Disk Prior to v7.7.4
Weaknesses CWE-264
CWE-285

Wed, 12 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.
References

Subscriptions

Cpsd Cryptopro Secure Disk
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:34:47.830Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59326

cve-icon Vulnrichment

Updated: 2026-08-13T15:34:41.956Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T14:17:46.713

Modified: 2026-09-01T21:09:48.053

Link: CVE-2025-59326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure