CVE-2025-59326
Received
Received - Intake
CPSD CryptoPro Secure Disk IMA Policy Bypass via Temporary Filesystems
Vulnerability report for CVE-2025-59326, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-12
Last updated on: 2026-08-12
Assigner: MITRE
Description
Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cpsd | cryptopro_secure_disk | to 7.7.4 (exc) |
| cpsd | crypto_pro_secure_disk_for_bitlocker | to 7.7.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |