CVE-2025-59322: CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allow...
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
Security readout for executives and security teams
Plain-English summary
CPSD CryptoPro Secure Disk for Bitlocker versions before 7.7.4 may mishandle decryption failures, allowing a supposedly encrypted volume to mount as readable plaintext. This could expose sensitive data without changing or disrupting it. Organizations using this product should quickly identify affected installations and update them.
Executive priority
Treat this as a high-priority confidentiality issue wherever CPSD protects sensitive data. Begin inventory and upgrades promptly. Current evidence does not establish active exploitation, so prioritization should reflect data sensitivity, exposure, and deployment context rather than assuming a widespread emergency.
Technical view
The flaw is classified under CWE-329 and CWE-703. The supplied CVSS 3.1 score is 7.5 with network reachability, low complexity, no required privileges or interaction, and high confidentiality impact. The record attributes no integrity or availability impact. Detailed triggering conditions are not provided in the bundle.
Likely exposure
Exposure applies to CPSD CryptoPro Secure Disk for Bitlocker releases earlier than 7.7.4. The structured affected-product fields are incomplete and provide no CPEs, so automated vulnerability matching may miss installations. Actual exposure depends on product deployment and access to protected volumes.
Exploitation context
The CVE is not listed as KEV, and the supplied sources provide no evidence of active exploitation. The CVSS vector describes network reachability without privileges or user interaction, but the bundle does not explain the required deployment conditions or attack path.
Researcher notes
The record describes an error-handling failure that crosses an encryption trust boundary. CWE-329 and CWE-703 are assigned, but the bundle lacks implementation details, affected-platform specifics, CPEs, and confirmed detection indicators. Researchers should consult the referenced CPSD and Black Hat materials without assuming conditions absent from the record.
Mitigation direction
Upgrade affected CPSD installations to version 7.7.4 or later.
Confirm the supported upgrade path and any additional precautions in current CPSD vendor guidance.
Prioritize systems containing regulated, confidential, or high-value data.
Limit access to affected systems and protected volumes until remediation is verified.
Validation and detection
Inventory installed CPSD versions and identify every release earlier than 7.7.4.
Confirm remediated systems report version 7.7.4 or later.
Use vendor-approved validation to confirm decryption failures cannot expose volume contents.
Review available system and product logs for unexpected mounts associated with decryption failures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-329: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-329 · source CWE mapping
Generation of Predictable IV with CBC Mode
Generation of Predictable IV with CBC Mode represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
Improper Check or Handling of Exceptional Conditions
Improper Check or Handling of Exceptional Conditions represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.