GHSA-5vmp-mmw3-vwr3HighCVSS 7.2
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the...
🔗 CVE IDs covered (1)
📋 Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2025-59319
- https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity-Wednesday.pdf
- https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity-wp.pdf
- https://www.cpsd.at/blog
- https://github.com/advisories/GHSA-5vmp-mmw3-vwr3