Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-59323

CVE-2025-59323: CryptoPro Secure Disk RCE Vulnerability

CVE-2025-59323 is a remote code execution vulnerability in CPSD CryptoPro Secure Disk for Bitlocker that enables attackers to execute code with high privileges. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-59323 Overview

CVE-2025-59323 affects CPSD CryptoPro Secure Disk for Bitlocker versions prior to v7.7.4. The product fails to validate the integrity of its DataStore, a non-partitioned filesystem that holds configuration and cryptographic material. Attackers who supply crafted DataStore contents can disrupt service availability or execute code in a high-privilege context. The flaw was documented in the Black Hat USA 2026 presentation "The Cost of Obscurity" by Burch.

Critical Impact

Crafted DataStore contents can trigger code execution with high privileges on systems running vulnerable CryptoPro Secure Disk for Bitlocker builds, undermining pre-boot disk encryption trust.

Affected Products

  • CPSD CryptoPro Secure Disk for Bitlocker versions before v7.7.4
  • Endpoints using CPSD pre-boot authentication with BitLocker integration
  • Systems relying on the CPSD DataStore for configuration and cryptographic details

Discovery Timeline

  • 2026-08-12 - CVE-2025-59323 published to NVD
  • 2026-08-12 - Last updated in NVD database
  • Vulnerability details presented at Black Hat USA 2026 in "The Cost of Obscurity" by Burch

Technical Details for CVE-2025-59323

Vulnerability Analysis

CryptoPro Secure Disk for Bitlocker (CPSD) provides pre-boot authentication and integrates with Microsoft BitLocker. The product stores configuration data and cryptographic material in a DataStore, described by the vendor as a non-partitioned filesystem structure. Versions prior to v7.7.4 do not verify the integrity of this DataStore before consuming its contents. An attacker who can modify DataStore contents can influence parsing and execution paths in a component that runs with elevated privileges. The result is either a denial-of-service condition or arbitrary code execution in a high-privilege context. Full technical analysis appears in the Black Hat USA 2026 materials referenced below.

Root Cause

The root cause is missing integrity validation of a security-critical data structure. The DataStore is treated as trusted input despite carrying configuration and cryptographic details that influence control flow. Without a cryptographic check such as a signature or authenticated hash, tampered contents pass validation and are processed as legitimate.

Attack Vector

Exploitation requires an actor able to write crafted contents to the CPSD DataStore. That access pattern is consistent with local tampering scenarios against the pre-boot environment or offline modification of the storage medium. Once the modified DataStore is loaded, parsing logic in the privileged CPSD component processes the attacker-controlled data and yields either a crash or code execution at high privilege.

No verified public exploit code is available. See the Black Hat White Paper: Cost of Obscurity and the Black Hat Presentation: Cost of Obscurity for technical detail.

Detection Methods for CVE-2025-59323

Indicators of Compromise

  • Unexpected modification timestamps on CPSD DataStore regions or associated pre-boot artifacts.
  • CPSD service or driver crashes and restarts without a preceding configuration change.
  • Privileged process spawning from CPSD components with unusual child processes or command lines.

Detection Strategies

  • Monitor CPSD binary and configuration paths for write operations from non-installer processes.
  • Alert on anomalous privileged execution originating from CPSD-related services or drivers.
  • Compare deployed CPSD version against v7.7.4 across the fleet and flag lagging endpoints.

Monitoring Recommendations

  • Collect endpoint telemetry covering process creation, driver load, and disk write events on encrypted hosts.
  • Track boot integrity events and BitLocker recovery prompts, which may indicate pre-boot tampering.
  • Review the CPSD Blog on Security for vendor updates and additional guidance.

How to Mitigate CVE-2025-59323

Immediate Actions Required

  • Upgrade CPSD CryptoPro Secure Disk for Bitlocker to v7.7.4 or later on every affected endpoint.
  • Inventory systems using CPSD and prioritize upgrade for laptops and other high-exposure devices.
  • Restrict physical access to systems that cannot yet be patched to limit offline DataStore tampering.

Patch Information

CPSD addresses the missing integrity validation in v7.7.4. Consult the CPSD Blog on Security for release information and confirm deployment through vendor-supplied installers.

Workarounds

  • Enforce full-disk encryption plus TPM-backed BitLocker protectors to raise the cost of offline modification.
  • Enable Secure Boot and firmware passwords to reduce the pre-boot attack surface.
  • Limit local administrative rights so unauthorized users cannot stage crafted DataStore content.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.