External risk intelligence

CPSD CryptoPro Secure Disk TPM PCR Policy Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-59321

This vulnerability affects disk encryption software (TPM PCR policy) residing on a local endpoint. It requires physical access or localized manipulation of the hardware boot state to exploit. It is not a network-accessible service, web application, or edge device, and there is no mechanism for remote exploitation over the public internet.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in CryptoPro Secure Disk for Bitlocker that could allow an attacker to unseal encrypted data through an unintended execution path or from different hardware. This issue arises from a default setting in the Trusted Platform Module (TPM) policy that does not properly account for the system's boot state. The primary concern is to confirm whether this specific technology is in use and if there is any potential exposure.

  • Flaw allows unintended disk data access.
  • Confirms if this technology is in use.
  • Assess relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by manipulating the system's boot process or by moving the Trusted Platform Module (TPM) to another machine. This could allow them to unseal encrypted disk data through an unintended execution path, potentially leading to unauthorized access to sensitive information.

  • No entry conditions required.
  • Triggered by unintended execution path.
  • Allows unauthorized data access.

Live Threat

Current exploitation, exposure, and threat context

When the default TPM PCR policy in CPSD CryptoPro Secure Disk for Bitlocker is not properly considered during system boot, the Trusted Platform Module (TPM) could be unsealed through an unintended execution path or when migrated to different hardware. This could allow unauthorized access to the encrypted disk data when supported by the advisory's conditions.

  • Encrypted disk data may be at risk.
  • TPM unsealing could occur unexpectedly.
  • Unauthorized data access may result.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in CryptoPro Secure Disk for Bitlocker requires an assessment of local endpoint security. Infrastructure or platform teams managing the affected disk encryption software should initiate an inventory of all deployments. The first practical step is to confirm whether any instances are exposed to an unintended execution path or on an alternative hardware platform, identify the business criticality of each instance, and then coordinate remediation with the accountable owner based on the assessed risk.

  • Identify accountable system owners.
  • Verify TPM PCR policy configurations.
  • Plan coordinated remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is CPSD CryptoPro Secure Disk for Bitlocker?

This software is an encryption management tool designed to secure data on endpoints. It works with the Trusted Platform Module (TPM) on your hardware to ensure that disk data remains protected. By managing specific boot policies, it controls when the system unlocks encrypted drives during the startup process.

What does CWE-1188 mean for CVE-2025-59321?

CWE-1188 refers to the use of insecure default initialization or configuration settings. In the case of CVE-2025-59321, the vulnerability exists because the software's default TPM policy is too permissive. It fails to verify the system's integrity during boot, allowing the encryption keys to be released even when the environment may not be secure.

How is this TPM vulnerability triggered?

The issue is triggered when the disk encryption software fails to account for the current system boot state. It does not require complex remote commands; instead, an attacker could potentially unseal the data by manipulating the boot process or moving the TPM hardware to an unauthorized device. Standard, secure boot operations do not trigger this flaw.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this vulnerability is very unlikely to be exploited remotely. Because it resides on local endpoint hardware and requires physical or localized boot-level manipulation, it is not a network-accessible target. You should focus your attention on endpoints where someone could physically access or modify the boot sequence.

How do I respond to this advisory?

Start by identifying all systems in your environment running CPSD CryptoPro Secure Disk for Bitlocker. Once you have a clear inventory, prioritize high-value assets and verify your current TPM PCR policy configurations. Coordinate with your system administration or platform teams to ensure that these configurations are updated to properly validate the system boot state.

References