CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
History

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Secure Disk
Vendors & Products Cpsd
Cpsd cryptopro Secure Disk

Wed, 12 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Boot Partition Selection in CryptoPro Secure Disk

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-12T19:24:46.816Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59319

cve-icon Vulnrichment

Updated: 2026-08-12T19:24:41.206Z

cve-icon NVD

Status : Received

Published: 2026-08-12T15:17:28.963

Modified: 2026-08-12T20:17:32.773

Link: CVE-2025-59319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:45:02Z