Impact
A flaw in the bootxsa.efi component of CPSD CryptoPro Secure Disk for Bitlocker prevents proper validation of LUKS encryption when present, causing all CryptoPro integrity checks to be skipped. This allows an attacker to introduce malicious modifications into the boot environment undetected, compromising the integrity of the operating system and data. The weakness is missing integrity verification (CWE‑347).
Affected Systems
The vulnerability affects systems running CPSD CryptoPro Secure Disk for Bitlocker versions prior to 7.7.4. Users of this software should verify whether they are on an affected build and consider updating as soon as possible to remove the risk.
Risk and Exploitability
Based on the description, it is inferred that the flaw requires local or privileged access to modify the boot media or encrypted disk. The likely attack vector is the alteration of the encrypted disk image before boot, which would bypass integrity checks. No public exploitation evidence exists. The EPSS score of < 1% indicates a very low exploitation probability, while the CVSS score of 7.5 denotes high severity. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment