Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft

## Cybersecurity: Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker

Cybersecurity: Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker

Multiple vulnerabilities have been identified in CryptoPro Secure Disk (CPSD) for BitLocker, an encryption solution employed by various organizations.

These vulnerabilities could allow attackers with physical access to devices to gain root access and potentially steal sensitive credentials.

CVE CVSS Details

CVE-2025-10010 N/A Integrity bypass enabling root code execution.

N/A N/A Cleartext /tmp data exposes credentials.

The vulnerability, identified as CVE-2025-10010, involves an integrity validation bypass. CryptoPro Secure Disk employs a minimal Linux operating system for authentication before decrypting the Windows partition using BitLocker.

This Linux system is located on an unencrypted partition, accessible to anyone with physical access to the hard drive or who can boot from an external medium.

Multiple vulnerabilities have been identified in CryptoPro Secure Disk (CPSD) for BitLocker, an encryption solution employed by various organizations.
Hazel Caldwell · Thehackingpost

While the system uses the Linux kernel's Integrity Measurement Architecture (IMA) for file verification, researchers found that IMA does not validate certain configuration files.

By manipulating these files, an attacker can execute arbitrary code with root privileges, allowing potential monitoring or data access without triggering errors.

Product Vulnerable Versions Fixed Versions

CPSD CryptoPro Secure Disk < 7.6.6 / < 7.7.1 7.6.6 / 7.7.1

The second issue involves the storage of sensitive data in clear text. When users forget their credentials, CryptoPro Secure Disk connects to a predefined network for support, storing necessary secrets such as certificates and passwords in cleartext within the temporary /tmp folder.

Advertisement

An attacker who gains access to the Linux environment could easily read these files, potentially compromising internal networks or bypassing network access controls.

The vendor was notified of these issues in June 2025. Patches addressing the vulnerabilities are available in versions 7.6.6 and 7.7.1.

Organizations using CryptoPro Secure Disk should update their software immediately. If updating is not feasible, encrypting the PBA partition is recommended, a feature available since version 7.6.0. From version 7.7, this encryption is enabled by default, reducing the risk of unauthorized file modifications.

SEC Consult advises comprehensive security reviews of encryption solutions to identify and mitigate potential weaknesses.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories