CyberRota Analysis
AI-GeneratedCPSD CryptoPro Secure Disk for Bitlocker versions prior to 7.7.4 are vulnerable due to a default TPM PCR policy that does not account for the system boot state, potentially allowing unauthorized access to sensitive data through unintended execution paths or alternative hardware platforms. Organizations utilizing this software should prioritize remediation to mitigate the risk of data exposure and unauthorized access.
CVE
CVE-2025-59321
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%
Original NVD Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.