Sceawere

Vulnerability Detail

CVE-2025-59319UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CryptoPro Secure Disk Partition Spoofing Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
7h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-12T15:17:28.963Z",
  "pubdate": "2026-08-12T15:17:28.963Z",
  "executiveSummary": "CPSD CryptoPro Secure Disk for Bitlocker prior to version 7.7.4 suffers from a partition selection and integrity validation vulnerability in its boot process.\nThe vulnerability allows an attacker with physical or low-level storage access to manipulate the partition layout by inserting a crafted Linux partition ahead of the intended target.\nThis flaw enables arbitrary code execution within the context of high privileges during the boot sequence, compromising the integrity of the encrypted environment.\nThe root cause stems from the boot component failing to cryptographically certify the integrity of the intended boot partition and instead relying on a deterministic search that selects the first partition index matching a hardcoded type value.\nSuccessful exploitation requires the ability to modify or craft partition tables on the target storage medium, posing significant risk to environments where unauthorized physical or administrative storage manipulation is possible.",
  "technicalDetails": "The vulnerability resides in the boot partition resolution mechanism of CPSD CryptoPro Secure Disk for Bitlocker in versions prior to 7.7.4.\nDuring the initialization and boot phase, the software attempts to locate and load the designated boot partition to continue the secure boot sequence.\nHowever, the implementation lacks integrity certification mechanisms, meaning it does not cryptographically verify that the target partition matches the expected state or identity.\nInstead of validating partition attributes securely, the parsing logic employs a flawed discovery algorithm that iterates through the partition table and selects the very first partition index that matches a specific hardcoded type value.\nAn attacker can exploit this deterministic behavior by modifying the Master Boot Record (MBR) or GUID Partition Table (GPT) to introduce a crafted Linux partition placed sequentially ahead of the legitimate target partition.\nWhen the vulnerable boot component scans the storage medium, it encounters the attacker-supplied partition first, falsely identifies it as the intended target due to the matching hardcoded type value, and proceeds to interact with or execute data from it.\nThis condition leads to arbitrary code execution in the context of high privileges during the early boot stages, bypassing intended security boundaries enforced by the disk encryption solution.\nThe attack requires low-level write access to the storage medium to alter the partition table structure, typically manifesting as physical access or prior compromise of the host system's storage configuration."
}
CVE-2025-59319: CryptoPro Secure Disk Partition Spoofing Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere