CVE-2025-59321
Deferred
Deferred - Pending Action
Default TPM PCR Policy Bypass in CryptoPro Secure Disk
Vulnerability report for CVE-2025-59321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-12
Last updated on: 2026-08-31
Assigner: MITRE
Description
Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cpsd | crypto_pro_secure_disk | to 7.7.4 (exc) |
| cpsd | cryptopro_secure_disk | to 7.7.4 (exc) |
| cpsd | cryptopro_secure_disk_for_bitlocker | to 7.7.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1188 | The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure. |