Vulnerability Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity
- https://i.blackhat.com/BH-USA-26/Presentations/US-26-Burch-The-Cost-of-Obscurity
- https://www.cpsd.at/blog/
FAQ
What is CVE-2025-59323?
CVE-2025-59323 is a vulnerability with a CVSS score of 8.4 (HIGH). CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. ...
How severe is CVE-2025-59323?
CVE-2025-59323 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59323?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.