Vulnerability Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity
- https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity
- https://www.cpsd.at/blog/
FAQ
What is CVE-2025-59319?
CVE-2025-59319 is a vulnerability with a CVSS score of 7.2 (HIGH). CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Li...
How severe is CVE-2025-59319?
CVE-2025-59319 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59319?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.